{"data":{"id":"425222de-64ed-4de1-9f67-408298cc2614","title":"CVE-2026-95660: A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function o","summary":"A security flaw was found in Moonshot AI Kimi Code up to version 0.31.0 that allows OS command injection (running unauthorized system commands) through the MCP Configuration Loader component. An attacker can exploit this vulnerability remotely, and the exploit code has been publicly released.","solution":"Upgrade to version 0.31.1. The fix resolves fd/stty binaries to absolute paths (using full file paths instead of searching standard directories) so that untrusted workspaces cannot plant bare-name executables before confirmation, preventing attackers from hijacking commands through $PATH path-planting (placing malicious programs in directories where the system searches for commands).","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-95660","publishedAt":"2026-09-22T18:17:37.750Z","cveId":"CVE-2026-95660","cweIds":["CWE-77","CWE-78"],"cvssScore":"6.3","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Moonshot AI","Kimi Code"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-22T18:17:37.750Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","availability"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}