Security Advisory
CVE-2025-11445
6.3
MEDIUM
Vulnerability Description
A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing manipulation results in injection. The attack can be initiated remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue.
Published Date
October 8, 2025
Official Source
NIST NVD Advisory