{"id":"CVE-2026-8765","summary":"Kilo-Org kilocode File Diff API Endpoint worktree-diff.ts Bun.file path traversal","details":"A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component File Diff API Endpoint. Performing a manipulation of the argument File results in path traversal. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.","modified":"2026-07-15T01:48:53.421419310Z","published":"2026-05-17T22:00:13.413Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.0"},{"introduced":"7.0.1"},{"last_affected":"7.0.1"},{"introduced":"7.0.2"},{"last_affected":"7.0.2"},{"introduced":"7.0.3"},{"last_affected":"7.0.3"},{"introduced":"7.0.4"},{"last_affected":"7.0.4"},{"introduced":"7.0.5"},{"last_affected":"7.0.5"},{"introduced":"7.0.6"},{"last_affected":"7.0.6"},{"introduced":"7.0.7"},{"last_affected":"7.0.7"},{"introduced":"7.0.8"},{"last_affected":"7.0.8"},{"introduced":"7.0.9"},{"last_affected":"7.0.9"},{"introduced":"7.0.10"},{"last_affected":"7.0.10"},{"introduced":"7.0.11"},{"last_affected":"7.0.11"},{"introduced":"7.0.12"},{"last_affected":"7.0.12"},{"introduced":"7.0.13"},{"last_affected":"7.0.13"},{"introduced":"7.0.14"},{"last_affected":"7.0.14"},{"introduced":"7.0.15"},{"last_affected":"7.0.15"},{"introduced":"7.0.16"},{"last_affected":"7.0.16"},{"introduced":"7.0.17"},{"last_affected":"7.0.17"},{"introduced":"7.0.18"},{"last_affected":"7.0.18"},{"introduced":"7.0.19"},{"last_affected":"7.0.19"},{"introduced":"7.0.20"},{"last_affected":"7.0.20"},{"introduced":"7.0.21"},{"last_affected":"7.0.21"},{"introduced":"7.0.22"},{"last_affected":"7.0.22"},{"introduced":"7.0.23"},{"last_affected":"7.0.23"},{"introduced":"7.0.24"},{"last_affected":"7.0.24"},{"introduced":"7.0.25"},{"last_affected":"7.0.25"},{"introduced":"7.0.26"},{"last_affected":"7.0.26"},{"introduced":"7.0.27"},{"last_affected":"7.0.27"},{"introduced":"7.0.28"},{"last_affected":"7.0.28"},{"introduced":"7.0.29"},{"last_affected":"7.0.29"},{"introduced":"7.0.30"},{"last_affected":"7.0.30"},{"introduced":"7.0.31"},{"last_affected":"7.0.31"},{"introduced":"7.0.32"},{"last_affected":"7.0.32"},{"introduced":"7.0.33"},{"last_affected":"7.0.33"},{"introduced":"7.0.34"},{"last_affected":"7.0.34"},{"introduced":"7.0.35"},{"last_affected":"7.0.35"},{"introduced":"7.0.36"},{"last_affected":"7.0.36"},{"introduced":"7.0.37"},{"last_affected":"7.0.37"},{"introduced":"7.0.38"},{"last_affected":"7.0.38"},{"introduced":"7.0.39"},{"last_affected":"7.0.39"},{"introduced":"7.0.40"},{"last_affected":"7.0.40"},{"introduced":"7.0.41"},{"last_affected":"7.0.41"},{"introduced":"7.0.42"},{"last_affected":"7.0.42"},{"introduced":"7.0.43"},{"last_affected":"7.0.43"},{"introduced":"7.0.44"},{"last_affected":"7.0.44"},{"introduced":"7.0.45"},{"last_affected":"7.0.45"},{"introduced":"7.0.46"},{"last_affected":"7.0.46"},{"introduced":"7.0.47"},{"last_affected":"7.0.47"}]}],"cna_assigner":"VulDB","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8765.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/8xxx/CVE-2026-8765.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8765"},{"type":"ADVISORY","url":"https://vuldb.com/submit/811401"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/364390"},{"type":"REPORT","url":"https://vuldb.com/vuln/364390/cti"},{"type":"EVIDENCE","url":"https://gist.github.com/YLChen-007/1770f4530b0c933dc61f15b02aa0629d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/kilo-org/kilocode","events":[{"introduced":"0"},{"last_affected":"702c27a8d2c21103079a43fc1e1b1d91f25c96df"}],"database_specific":{"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.47"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:kilo:kilo_code:*:*:*:*:*:visual_studio_code:*:*"}}],"versions":["v7.0.47","v7.0.46","v7.0.45","v7.0.44","v7.0.42","v7.0.43","v7.0.41","v7.0.40","v7.0.39","v7.0.38","v7.0.37","v7.0.36","v7.0.35","v7.0.34","v7.0.33","v7.0.32","v7.0.31","v7.0.30","v7.0.29","v7.0.28","v7.0.27","v7.0.26","v1.0.25","v1.0.24","v1.0.23","v1.0.22","v1.0.21","v1.0.20","v1.0.19","v1.0.18","v1.0.17","v1.0.14","v1.0.13","v1.0.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-8765.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"}]}