PT-2026-46005 · Moonshot Ai · Kimi Ai
CVSS v3.1
6.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Kimi AI version 1.0
Description
A Cross Site Scripting issue exists in the 'Preview' feature of the web interface. The application does not properly sanitize or encode HTML/JavaScript payloads generated by the AI model. When a user accesses the 'Preview' tab to view AI-generated code, the malicious payload is rendered directly into the Document Object Model (DOM), which is the programming interface for HTML and XML documents, allowing arbitrary JavaScript execution in the browser session.
Recommendations
Update Kimi AI version 1.0 to a version that properly sanitizes AI-generated content in the 'Preview' feature.
As a temporary workaround, avoid using the 'Preview' tab to view AI-generated code until a fix is applied.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kimi Ai