CVE-2026-79403
Description
AI Translation Available
An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint
https://gist.github.com/akinerkisa/e345af9f9992b87247a71fdb5b36ac2c
https://github.com/Kilo-Org/kilocode/commit/51e45d7fb7
https://github.com/Kilo-Org/kilocode/pull/11887