CVE-2026-79403

An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint

  • Published Sep 29, 2026
  • CVSS 8.4 high
  • 0.1% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

CVE-2026-79403 at the National Vulnerability Database