---
id: CVE-2026-79403
title: >-
  An issue in Kilo Code before v7.4.1 allows a local attacker to execute
  arbitrary code via the permission/allow-everything endpoint
summary: >-
  An issue in Kilo Code before v7.4.1 allows a local attacker to execute
  arbitrary code via the permission/allow-everything endpoint
severity: none
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T20:17:26.737'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79403'
references:
  - url: 'https://gist.github.com/akinerkisa/e345af9f9992b87247a71fdb5b36ac2c'
    label: cve@mitre.org
  - url: 'https://github.com/Kilo-Org/kilocode/commit/51e45d7fb7'
    label: cve@mitre.org
  - url: 'https://github.com/Kilo-Org/kilocode/pull/11887'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T20:46:06.449Z'
---

## Overview

An issue in Kilo Code before v7.4.1 allows a local attacker to execute arbitrary code via the permission/allow-everything endpoint

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
