Arbitrary Code Execution in JetBrains GoLand Affected by Vulnerability
CVE-2026-64802
7.8HIGH
What is CVE-2026-64802?
In GoLand prior to version 2026.2, the software allowed arbitrary code execution due to insufficient trust validation before granting project trust in the Go Modules integration. This defect may enable attackers to execute unauthorized commands and potentially compromise the integrity of a user's project.
Affected Version(s)
GoLand 0 < 2026.2