CVE-2026-79403 | Kilo Code up to 7.4.0 Permission Allow-Everything Endpoint os command injection
A vulnerability, which was classified as problematic, was found in Kilo Code up to 7.4.0. The impacted element is an unknown function of the component Permission Allow-Everything Endpoint. Such manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-79403. The attack can only be performed from a local environment. No exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More