CVE-2026-53914
published 2026-06-26CVE-2026-53914: In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.20%
9.6th percentile
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jetbrains | kotlin | < 2.4.20 | 2.4.20 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution
ghsa·2026-06-26
CVE-2026-53914 [MEDIUM] CWE-502 JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution
JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
GHSA
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
ghsa_unreviewed·2026-06-26
CVE-2026-53914 [MEDIUM] CWE-502 In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-26
Published