Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Mgtx2

#45200of 56,330
6.3Total CVSS
Vulnerabilities · 1
PT-2026-46005
6.3
2026-06-03
Moonshot Ai · Kimi Ai · CVE-2026-39107
**Name of the Vulnerable Software and Affected Versions** Kimi AI version 1.0 **Description** A Cross Site Scripting issue exists in the 'Preview' feature of the web interface. The application does not properly sanitize or encode HTML/JavaScript payloads generated by the AI model. When a user accesses the 'Preview' tab to view AI-generated code, the malicious payload is rendered directly into the Document Object Model (DOM), which is the programming interface for HTML and XML documents, allowing arbitrary JavaScript execution in the browser session. **Recommendations** Update Kimi AI version 1.0 to a version that properly sanitizes AI-generated content in the 'Preview' feature. As a temporary workaround, avoid using the 'Preview' tab to view AI-generated code until a fix is applied.