CVE-2026-64803
Published Jul 23, 2026In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
8 CVEs tagged to jetbrains / goland — 2 Critical, 4 High, 1 Medium, 1 Low, 0 Unrated.
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK
In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration
In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default
In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3;…
JetBrains IntelliJ IDEA 2021.3.1 Preview, IntelliJ IDEA 2021.3.1 RC, PyCharm Professional 2021.3.1 RC, GoLand 2021.3.1, PhpStorm 2021.3.1 Preview, PhpStorm 2021.3.1 RC, RubyMine 2…
In JetBrains GoLand before 2019.3.2, the plugin repository was accessed via HTTP instead of HTTPS.