CVE-2026-79294: Moonshot AI Kimi vulnerability
Published Sep 18, 2026
·Updated
Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component
Affected Software
1 affected component
Moonshot AI Kimi=
Event History
Sep 18, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are exposed?
The affected component is the public Share view used for HTML artifact Preview rendering. Exposure therefore concerns Kimi content made available through that public sharing path.
2
What interaction is involved in exploitation?
The reported attack path requires HTML artifact content to be rendered in Preview through the public Share view. The issue is described as remotely exploitable.