Junglewise Threat Intelligence

CVE-2026-8766: Kilo-Org kilocode arbitrary file disclosure in Environment Variable Handler

CVE-2026-8766 · Severity: medium · CVSS 4.3 · Published 2026-05-17

Vendors: npm.

Executive brief

The Kilo-Org kilocode CLI, a tool used for development and configuration management, is vulnerable to an information disclosure flaw. An attacker who can manipulate environment variables can trick the tool into reading sensitive local files, such as system passwords or private keys. This information is then leaked through error messages, potentially allowing an unauthorized actor to gain deeper access to the system or cloud environment.

Technical details

An arbitrary file read vulnerability exists in @kilocode/cli versions up to 7.0.47 due to unsafe token substitution in the Environment Variable Handler. The 'Load' function in 'packages/opencode/src/config/config.ts' processes the 'KILO_CONFIG_CONTENT' environment variable and improperly evaluates '{file:/path}' templates before performing schema validation. By injecting a payload with an unrecognized JSON key containing this template, an attacker can force the application to read a local file. The file's contents are subsequently leaked in the resulting Zod schema validation error traceback sent to stderr. This issue represents a regression or incomplete remediation of a similar flaw previously patched in the legacy 'OPENCODE_CONFIG_CONTENT' variable.

Affected products

  • Kilo-Org kilocode/cli <= 7.0.47

Timeline

  • 2026-04-04: other: Vulnerability details and PoC shared in a public Gist
  • 2026-05-17: disclosed: NVD publication date
  • 2026-05-18: advisory: GitHub Advisory published

References

Related threats