CVE-2026-95660: A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function o
Summary
A security flaw was found in Moonshot AI Kimi Code up to version 0.31.0 that allows OS command injection (running unauthorized system commands) through the MCP Configuration Loader component. An attacker can exploit this vulnerability remotely, and the exploit code has been publicly released.
Solution / Mitigation
Upgrade to version 0.31.1. The fix resolves fd/stty binaries to absolute paths (using full file paths instead of searching standard directories) so that untrusted workspaces cannot plant bare-name executables before confirmation, preventing attackers from hijacking commands through $PATH path-planting (placing malicious programs in directories where the system searches for commands).
Vulnerability Details
6.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
network
low
none
required
September 22, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-95660
First tracked: September 22, 2026 at 08:09 PM
Classified by LLM (prompt v3) · confidence: 75%