Impact
The vulnerability is a cross‑site scripting flaw that allows a remote attacker to execute arbitrary code via the HTML artifact preview rendering in the public Share view component. The attack vector relies on the attacker crafting a malicious HTML artifact that is then rendered by the Share view, leading to execution of injected scripts. The impact is a full compromise of the affected system’s confidentiality, integrity, and availability.
Affected Systems
Moonshot AI Kimi, any version as of 2026‑07‑18. No specific version details are available.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score is < 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw by accessing the public Share view component and delivering a malicious HTML artifact. No additional privileged access or local conditions are required.
OpenCVE Enrichment