Home

Description

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

PUBLISHED Reserved 2026-06-11 | Published 2026-06-26 | Updated 2026-06-26 | Assigner JetBrains




MEDIUM: 6.7CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L

Problem types

CWE-502

Product status

Default status
unaffected

Any version before 2.4.20
affected

References

www.jetbrains.com/privacy-security/issues-fixed/

cve.org (CVE-2026-53914)

nvd.nist.gov (CVE-2026-53914)

Download JSON