Cross Site Scripting Vulnerability in Moonshot AI Kimi Product
CVE-2026-79294

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-79294?

A Cross Site Scripting vulnerability exists in the Moonshot AI Kimi product that allows remote attackers to execute arbitrary code. This vulnerability is triggered through the HTML artifact Preview rendering within the public Share view component, leading to potential unauthorized access or manipulation of user interactions. Users are encouraged to apply security patches and update their software to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.