CVE-2025-11445: Kilo Code Prompt ClineProvider.ts ClineProvider injection
A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing manipulation results in injection. The attack can be initiated remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11445?
CVE-2025-11445 is considered a high severity vulnerability due to its potential for remote code injection.
How do I fix CVE-2025-11445?
To fix CVE-2025-11445, upgrade Kilo Code Prompt Handler to version 4.86.1 or later.
What component is affected by CVE-2025-11445?
CVE-2025-11445 affects the Prompt Handler component in Kilo Code.
How is CVE-2025-11445 exploited?
CVE-2025-11445 can be exploited remotely through manipulation of the ClineProvider function.
Which versions of Kilo Code are impacted by CVE-2025-11445?
Versions of Kilo Code up to and including 4.86.0 are impacted by CVE-2025-11445.