PT-2025-41241 · Kilo Code · Kilo Code

Echarris128

·

Published

2025-10-08

·

Updated

2025-10-08

·

CVE-2025-11445

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Kilo Code versions prior to 4.86.0
Description A flaw exists in Kilo Code that allows for injection through manipulation of the ClineProvider function within the src/core/webview/ClineProvider.ts file of the Prompt Handler component. This issue can be exploited remotely. The exploit is publicly available. The vulnerable component is the Prompt Handler.
Recommendations Apply a patch to address this issue.

Exploit

Fix

Improper Neutralization

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2025-11445

Affected Products

Kilo Code