Security Advisory

CVE-2025-11445

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-08 08:32:07
Last updated 2025-10-08 13:09:54
Assigner VulDB
CVSS score 5.3
State PUBLISHED

Description

A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing manipulation results in injection. The attack can be initiated remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue.