CVE-2026-95660 Details
Description
A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function of the file agent-core-v2/src/agent/mcp/config-loader.ts of the component MCP Configuration Loader. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.31.1 is sufficient to fix this issue. It is recommended to upgrade the affected component. Beyond the trust prompt, the fix resolves fd/stty binaries to absolute paths specifically "so untrusted workspaces cannot plant bare-name executables before confirmation," fixing a secondary $PATH path-planting vector alongside the primary untrusted-.mcp.json auto-spawn.
An OS command injection vulnerability has been identified in Moonshot AI Kimi Code versions through 0.31.0. The issue arises in the MCP Configuration Loader component, specifically within an unknown function of the file agent-core-v2/src/agent/mcp/config-loader.ts. This vulnerability can be exploited remotely, and the released public exploit allows for arbitrary command execution on the operating system.
Users can upgrade to Moonshot AI Kimi Code version 0.31.1 to address this vulnerability. This version is available on the Moonshot AI Kimi Code GitHub Releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 22, 2026CISA-ADP
Assessed Sep 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.google.com/document/d/1GPDw0UzUkgfXRkWEDqCIanKDq3Tpvllyf08O-0eLyoQ/edit?tab=t.0 | CISA-ADP | |
| https://docs.google.com/document/d/1GPDw0UzUkgfXRkWEDqCIanKDq3Tpvllyf08O-0eLyoQ/edit?usp=sharing | [email protected] | ExploitPermission Required |
| https://github.com/MoonshotAI/kimi-code/releases/tag/%40moonshot-ai%2Fkimi-code%400.31.1 | [email protected] | Release NotesVendor |
| https://vuldb.com/cve/CVE-2026-95660 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/897071 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/408415 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/408415/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Moonshot AI Kimi Code | <= 0.31.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | CISA-ADP |
| Sep 22, 2026 | New CVE Received | [email protected] |
Volerion