Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component
Medium CVSS 6.1
Summary
Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- http://kimi.com
- http://moonshot.com
- https://github.com/MGTx2/CVE-2026-79294/blob/main/README.md
- https://kimi.com/share/
- https://github.com/MGTx2/CVE-2026-79294/blob/main/README.md
Timeline
- nvd_ingest NVD