{"id":"CVE-2026-79403","published":"2026-09-29T20:17:26.737","lastModified":"2026-09-29T20:17:26.737","description":"An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://gist.github.com/akinerkisa/e345af9f9992b87247a71fdb5b36ac2c","tags":[]},{"url":"https://github.com/Kilo-Org/kilocode/commit/51e45d7fb7","tags":[]},{"url":"https://github.com/Kilo-Org/kilocode/pull/11887","tags":[]}],"exploitRefs":[{"url":"https://gist.github.com/akinerkisa/e345af9f9992b87247a71fdb5b36ac2c","tags":[]},{"url":"https://github.com/Kilo-Org/kilocode/commit/51e45d7fb7","tags":[]},{"url":"https://github.com/Kilo-Org/kilocode/pull/11887","tags":[]}],"hasPoc":true,"ai":null}