CVE-2026-79403

Published: Set 29, 2026 Last Modified: Set 29, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint

https://gist.github.com/akinerkisa/e345af9f9992b87247a71fdb5b36ac2c
https://github.com/Kilo-Org/kilocode/commit/51e45d7fb7
https://github.com/Kilo-Org/kilocode/pull/11887