PT-2025-41241 · Kilo Code · Kilo Code
Echarris128
·
Published
2025-10-08
·
Updated
2025-10-08
·
CVE-2025-11445
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Kilo Code versions prior to 4.86.0
Description
A flaw exists in Kilo Code that allows for injection through manipulation of the
ClineProvider function within the src/core/webview/ClineProvider.ts file of the Prompt Handler component. This issue can be exploited remotely. The exploit is publicly available. The vulnerable component is the Prompt Handler.Recommendations
Apply a patch to address this issue.
Exploit
Fix
Improper Neutralization
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kilo Code