CVE-2026-64803

JetBrains · GoLand

JetBrains GoLand contains a code injection vulnerability that may allow for arbitrary code execution if a user is induced to process malicious data.

Executive summary

A high-severity code injection vulnerability in JetBrains GoLand could allow unauthorized attackers to execute arbitrary code on the affected system.

Vulnerability

This flaw is identified as CWE-94, involving improper control of code generation. It requires user interaction and can be exploited by an unauthenticated attacker to achieve complete control over the affected process.

Business impact

With a CVSS score of 7.8, this vulnerability poses a substantial threat to the security of development workstations. Exploitation could result in the exfiltration of sensitive credentials or proprietary source code, potentially leading to supply chain compromise and significant business disruption.

Remediation

Immediate Action: Apply the vendor security update by upgrading to JetBrains GoLand version 2026.2 or newer.

Proactive Monitoring: Monitor developer workstations for anomalous outbound network connections or unexpected system behavior following the opening of untrusted projects.

Compensating Controls: Restrict the execution of unknown or untrusted project files within the IDE and enforce endpoint detection and response (EDR) policies to limit the impact of potential code execution.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the severity of the potential impact, rapid deployment of the latest security update is essential. Security teams should verify that all installations of GoLand are updated to version 2026.2 to ensure the vulnerability is fully remediated.