Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-11445

Опубликовано: 08 окт. 2025
Источник: nvd
CVSS3: 6.3
CVSS2: 7.5
EPSS Низкий

Описание

A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing manipulation results in injection. The attack can be initiated remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue.

EPSS

Процентиль: 18%
0.00057
Низкий

6.3 Medium

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 6.3
github
4 месяца назад

A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing manipulation results in injection. The attack can be initiated remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue.

EPSS

Процентиль: 18%
0.00057
Низкий

6.3 Medium

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74