Arbitrary Code Execution in JetBrains GoLand Affected by Vulnerability
CVE-2026-64802

7.8HIGH

Key Information:

Vendor

Jetbrains

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-64802?

In GoLand prior to version 2026.2, the software allowed arbitrary code execution due to insufficient trust validation before granting project trust in the Go Modules integration. This defect may enable attackers to execute unauthorized commands and potentially compromise the integrity of a user's project.

Affected Version(s)

GoLand 0 < 2026.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.