Showing 6 vulnerabilities on this page for GoLand

Signals CISA KEV Ransomware Nuclei
JetBrains vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Generated title:JetBrains GoLand Code Injection via Configured Go SDK

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK

CWE-94Jul 23, 2026
CVSS7.8v3.1EPSS0.143%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains GoLand Go Modules Integration Code Injection

In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration

CWE-94Jul 23, 2026
CVSS7.8v3.1EPSS0.143%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains GoLand Sensitive Configuration Information Disclosure in Log Files

In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default

CWE-532Jul 23, 2026
CVSS3.5v3.1EPSS0.491%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Generated title:JetBrains GoLand Remote Code Execution via Untrusted Project Configuration

In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration

CWE-73Jun 19, 2026
CVSS7.1v3.1EPSS0.288%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

In JetBrains GoLand before 2025.1 an XXE during debugging was possible

CWE-611Mar 25, 2025
CVSS4.1v3.1EPSS0.171%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

GitHub access token could be exposed to third-party sites in JetBrains IDEs after version 2023.1 and less than: IntelliJ IDEA 2023.1.7, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; Aqua 2024.1.2; CLion 2023.1.7, 2023.2.4, 2023.3.5, 2024.1.3, 2024.2 EAP2; DataGrip 2023.1.3, 2023.2.4, 2023.3.5, 2024.1.4; DataSpell 2023.1.6, 2023.2.7, 2023.3.6, 2024.1.2, 2024.2 EAP1; GoLand 2023.1.6, 2023.2.7, 2023.3.7, 2024.1.3, 2024.2 EAP3; MPS 2023.2.1, 2023.3.1, 2024.1 EAP2; PhpStorm 2023.1.6, 2023.2.6, 2023.3.7,

CWE-522Jun 10, 2024
CVSS9.3v3.1EPSS3.84%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX