LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-30302

CVE-2026-30302 - Vulnerability Analysis

CriticalCVSS: 10.0

Last Updated: March 27, 2026

CodeRider-Kilo - OS Command Injection

Published: March 27, 2026Updated: March 27, 2026Remote Exploitable

Overview

CodeRider-Kilo contains an OS command injection caused by improper command parsing and escape sequence handling in the auto-approval module on Windows, letting attackers bypass whitelist and execute arbitrary commands remotely, exploit requires Windows CMD environment.

Severity & Score

Severity: Critical
CVSS Score: 10.0
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can execute arbitrary commands remotely, bypassing whitelist protections and potentially taking full control of the system.

Mitigation

Update to the latest version with corrected command parsing and escape sequence handling for Windows CMD.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 27, 2026

šŸ”“ CVE-2026-30302 - Critical (10) The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-b... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-30302/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 27, 2026

šŸ”“ CVE-2026-30302 - Critical (10) The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (the Unix-b... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-30302/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-30302
Severity
Critical
CVSS Score
10.0
Type
command_injection
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-78

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days