PT-2026-46005 · Moonshot Ai · Kimi Ai

·

CVE-2026-39107

·

Published

2026-06-03

·

Updated

2026-07-22

CVSS v3.1

6.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Kimi AI version 1.0
Description A Cross Site Scripting issue exists in the 'Preview' feature of the web interface. The application does not properly sanitize or encode HTML/JavaScript payloads generated by the AI model. When a user accesses the 'Preview' tab to view AI-generated code, the malicious payload is rendered directly into the Document Object Model (DOM), which is the programming interface for HTML and XML documents, allowing arbitrary JavaScript execution in the browser session.
Recommendations Update Kimi AI version 1.0 to a version that properly sanitizes AI-generated content in the 'Preview' feature. As a temporary workaround, avoid using the 'Preview' tab to view AI-generated code until a fix is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39107

Affected Products

Kimi Ai