@kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
- Severity:
- Low
Description
A flaw has been found in Kilo-Org kilocode up to 7.0.47. This issue affects the function Load of the file packages/opencode/src/config/config.ts of the component Environment Variable Handler. Executing a manipulation of the argument KILO_CONFIG_CONTENT can lead to information disclosure. It is possible to launch the attack remotely.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 7.0.47
References
Related Issues
- Exposure of Sensitive Information to an Unauthorized Actor in nanoid - CVE-2021-23566
- Potential exposure of tokens to an Unauthorized Actor - CVE-2022-21671
- EverShop is vulnerable to Unauthorized Order Information Access (IDOR) - CVE-2025-12919
- Exposure of Sensitive Information in simple-get - CVE-2022-0355
You might also like:
- Tags:
- npm
- @kilocode/cli
Anything's wrong? Let us know Last updated on May 28, 2026


