216.73.216.226

CVE-2025-11445

· Published 08/10/2025 09:15 · Modified 08/10/2025 19:38

Labels: CVE-2025-11445 2025-10-08CVE-2025-11445CWE-74[email protected]

Essential information

Published
08/10/2025 09:15
Modified
08/10/2025 19:38
Author
Creator
CVSS
5.3 MEDIUM (v3) 5.3 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing manipulation results in injection. The attack can be initiated remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
kilo code / kilo code cpe:2.3:a:kilo_code:kilo_code:<=4.86.0:*:*:*:*:*:*:*

References