A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Project Subscriptions

Vendors Products
Kilo Code Subscribe
Kilo Code Cli Subscribe
Kilo-org Subscribe
Kilocode Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 20 May 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Kilo kilo Code Cli
CPEs cpe:2.3:a:kilo:kilo_code:*:*:*:*:*:visual_studio_code:*:* cpe:2.3:a:kilo:kilo_code_cli:*:*:*:*:*:node.js:*:*
Vendors & Products Kilo kilo Code Cli

Tue, 19 May 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:kilo:kilo_code:*:*:*:*:*:visual_studio_code:*:*

Mon, 18 May 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 18 May 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Kilo
Kilo kilo Code
Vendors & Products Kilo
Kilo kilo Code

Sun, 17 May 2026 22:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Kilo-Org kilocode Environment Variable config.ts load information disclosure
First Time appeared Kilo-org
Kilo-org kilocode
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:kilo-org:kilocode:*:*:*:*:*:*:*:*
Vendors & Products Kilo-org
Kilo-org kilocode
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-05-18T17:51:42.789Z

Reserved: 2026-05-17T08:55:27.777Z

Link: CVE-2026-8766

cve-icon Vulnrichment

Updated: 2026-05-18T15:52:31.725Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-17T23:17:02.640

Modified: 2026-05-20T17:34:04.830

Link: CVE-2026-8766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-19T23:00:13Z