CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

jetbrains

kotlin

6 known vulnerabilities · sorted by CVSS score

CVE-2020-15824
HIGH8.8

In JetBrains Kotlin from 1.4-M1 to 1.4-RC (as Kotlin 1.3.7x is not affected by the issue. Fixed version is 1.4.0) there is a script-cache privilege escalation vulnerability due to kotlin-main-kts cached scripts in the system temp directory, which is shared by all users by default.

jetbrains / kotlin+7
Network
Published Aug 8, 2020
CVE-2019-10102
HIGH8.1

JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed in Kotlin plugin version 1.3.30.

jetbrains / kotlin+1
Network
Published Jul 3, 2019
CVE-2019-10103
HIGH8.1

JetBrains IntelliJ IDEA projects created using the Kotlin (JS Client/JVM Server) IDE Template were resolving Gradle artifacts using an http connection, potentially allowing an MITM attack. This issue, which was fixed in Kotlin plugin version 1.3.30, is similar to CVE-2019-10101.

jetbrains / kotlin
Network
Published Jul 3, 2019
CVE-2019-10101
HIGH8.1

JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack.

jetbrains / kotlin
Network
Published Jul 3, 2019
CVE-2022-24329
MEDIUM5.3

In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.

jetbrains / kotlin+3
Network
Published Feb 25, 2022
CVE-2020-29582
MEDIUM5.3

In JetBrains Kotlin before 1.4.21, a vulnerable Java API was used for temporary file and folder creation. An attacker was able to read data from such files and list directories due to insecure permissions.

jetbrains / kotlin+3
Network
Published Feb 3, 2021