Medium severity6.7NVD Advisory· Published Jun 26, 2026· Updated Jun 27, 2026
CVE-2026-53914
CVE-2026-53914
Description
In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jetbrains.kotlin:kotlin-gradle-pluginMaven | < 2.4.20-Beta1 | 2.4.20-Beta1 |
Affected products
2Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-r937-wjx7-w2jpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-53914ghsaADVISORY
- www.jetbrains.com/privacy-security/issues-fixed/nvdVendor Advisory
- github.com/JetBrains/kotlin/commit/bf51df665b458fda7c3eaf436c4d88dc119d7ec6ghsaWEB
- github.com/JetBrains/kotlin/releases/tag/v2.4.20-Beta1ghsaWEB
- www.jetbrains.com/privacy-security/issues-fixedghsaWEB
News mentions
0No linked articles in our index yet.