CVE-2025-11445

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webview/ClineProvider.ts of the component Prompt Handler. Performing manipulation results in injection. The attack can be initiated remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue.

Published 2025-10-08. Last modified 2026-06-17.