Code Injection in GoLand - CVE-2026-64802
Published: August 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to code injection in the Go Modules integration when processing module-related project data before project trust is granted. A remote attacker can supply crafted content to execute arbitrary code.
Exploitation is possible before the user grants trust to the project.