In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Latest version: 2.4.10
End of life: 6/3/2026, Latest version: 2.3.21
End of life: 12/16/2025, Latest version: 2.2.21
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.