CVE-2026-79403: Kilo Code Kilo Code vulnerability
Published Sep 29, 2026
·Updated
An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint
Affected Software
1 affected component
Kilo Code Kilo Code<7.4.1
Event History
Sep 29, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Who can exploit this issue?
A local attacker can exploit it. The provided information does not indicate that remote access alone is sufficient.
2
Which versions need remediation?
Kilo Code versions before 7.4.1 are affected. Updating to version 7.4.1 or later addresses the reported issue.
3
What capability does successful exploitation provide?
Successful exploitation allows arbitrary code execution through the permission/allow-everything endpoint.