Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML… (CVE-2026-79294)
A Cross Site Scripting (XSS) vulnerability exists in Moonshot AI Kimi as of 2026-07-18. This flaw allows a remote attacker to execute arbitrary code through the HTML artifact Preview rendering in the public Share view component. The vulnerability has a medium severity with a CVSS score of 6.1. No affected versions or patch information are explicitly provided.
AI Analysis
Technical Summary
CVE-2026-79294 describes a Cross Site Scripting vulnerability in Moonshot AI Kimi affecting the HTML artifact Preview rendering feature within the public Share view component. This vulnerability enables remote attackers to execute arbitrary code by injecting malicious scripts. The CVSS 3.1 base score is 6.1, indicating medium severity, with attack vector network, low attack complexity, no privileges required, user interaction required, scope changed, and impacts on confidentiality and integrity but not availability.
Potential Impact
Successful exploitation could allow remote attackers to execute arbitrary code in the context of the affected application, potentially leading to unauthorized disclosure or modification of information. The vulnerability impacts confidentiality and integrity but does not affect availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided. Until a patch is available, users should exercise caution when interacting with the HTML artifact Preview rendering in the public Share view component.
Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML… (CVE-2026-79294)
Description
A Cross Site Scripting (XSS) vulnerability exists in Moonshot AI Kimi as of 2026-07-18. This flaw allows a remote attacker to execute arbitrary code through the HTML artifact Preview rendering in the public Share view component. The vulnerability has a medium severity with a CVSS score of 6.1. No affected versions or patch information are explicitly provided.
CVSS v3.1
Score 6.1medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-79294 describes a Cross Site Scripting vulnerability in Moonshot AI Kimi affecting the HTML artifact Preview rendering feature within the public Share view component. This vulnerability enables remote attackers to execute arbitrary code by injecting malicious scripts. The CVSS 3.1 base score is 6.1, indicating medium severity, with attack vector network, low attack complexity, no privileges required, user interaction required, scope changed, and impacts on confidentiality and integrity but not availability.
Potential Impact
Successful exploitation could allow remote attackers to execute arbitrary code in the context of the affected application, potentially leading to unauthorized disclosure or modification of information. The vulnerability impacts confidentiality and integrity but does not affect availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or patch information is provided. Until a patch is available, users should exercise caution when interacting with the HTML artifact Preview rendering in the public Share view component.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4mwh-5hjw-p5jv
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-79294"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aade51455bf5e2cf5edc00c
Added to database: 09/19/2026, 01:27:48 UTC
Last enriched: 09/19/2026, 01:41:00 UTC
Last updated: 09/19/2026, 04:01:23 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.