Path Traversal Vulnerability in Kilo-Org kilocode File Diff API Endpoint
CVE-2026-8765
Key Information:
Badges
What is CVE-2026-8765?
A vulnerability exists in Kilo-Org's kilocode up to version 7.0.47, specifically within the Bun.file function in the File Diff API Endpoint. This vulnerability allows attackers to perform a path traversal by manipulating the File argument, potentially leading to unauthorized access to sensitive files. The exploit is publicly available, and the issue can be triggered remotely. The vendor was notified about this security concern but has not yet responded.
Affected Version(s)
kilocode 7.0.0
kilocode 7.0.1
kilocode 7.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
