In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
History

Fri, 26 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unsafe Deserialization in Kotlin Build Cache Enables Code Execution

Fri, 26 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Description In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: JetBrains

Published:

Updated: 2026-06-26T13:44:35.494Z

Reserved: 2026-06-11T13:00:42.498Z

Link: CVE-2026-53914

cve-icon Vulnrichment

Updated: 2026-06-26T13:26:03.768Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T14:45:06Z