A AegiFlow
MEDIUMCVSS 6.7EPSS 0.2%

CVE-2026-53914

JetBrains Kotlin: Unsafe Deserialization in Kotlin Build Cache Enables Code Execution

Published
2026-06-26
Modified
2026-08-12
EPSS percentile
10%
Aliases
GHSA-r937-wjx7-w2jp
Sources
github-advisory

Summary

In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.jetbrains.kotlin:kotlin-gradle-plugin2.4.20-Beta1

Remediation: Upgrade to 2.4.20-Beta1 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.