In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata
Latest version: 2.4.10
In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.
End of life: 6/3/2026, Latest version: 2.3.21
End of life: 12/16/2025, Latest version: 2.2.21