CVE-2026-64802

JetBrains · GoLand

JetBrains GoLand is susceptible to code injection, potentially allowing an attacker to execute arbitrary code via malicious input.

Executive summary

A critical code injection vulnerability in JetBrains GoLand allows for unauthorized code execution, posing a significant risk to development environments.

Vulnerability

This vulnerability is classified as improper control of generation of code (CWE-94). It requires user interaction and can be triggered by an unauthenticated local attacker to achieve total system impact.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its high severity and potential for total compromise of the host system. Successful exploitation could lead to unauthorized access to source code, intellectual property theft, or the deployment of malicious payloads within the development pipeline, resulting in severe reputational and operational damage.

Remediation

Immediate Action: Update JetBrains GoLand to version 2026.2 or later immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Review system logs for unusual process execution or unauthorized file modifications originating from the GoLand application.

Compensating Controls: Ensure the application is running with the principle of least privilege and utilize endpoint security solutions to detect and block suspicious child processes spawned by development tools.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for code execution, this vulnerability represents a significant risk to software integrity. Organizations should prioritize patching all instances of JetBrains GoLand to version 2026.2 to mitigate this high-severity threat.