Skip to main content
EPSS 0.7%top 47%

Security update for kimi-code

0
Medium
Published: 09/14/2026 (09/14/2026, 13:20:22 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for kimi-code fixes the following issues: Changes in kimi-code: Update to version 0.42.0: * Add an experimental Updates panel with paginated progress messages from the main agent and subagents, enabled with KIMI_CODE_EXPERIMENTAL_NOTIFY_USER=1 * Turn the subagent model pool, Remote Control and the minidb session-index read model with the global search worker always on; their experimental flags and opt-out variables are gone, search persistence is now tuned via the [database] section * Give tower worker and reviewer briefings the full mission context, follow the subagent timeout for tower agents, and show each background agent's model in /tasks * Retrieve file search matches beyond the first 100 results, accept HEIC, HEIF and BMP images with Kimi-served models, and warn in kimi -p when project MCP servers are skipped in an untrusted folder * Read files with configurable character limits and resumable long-line reads, decode malformed UTF-16 with a warning, and preserve image and video filenames in session history * Rework the dashboard: deletable sessions, reorderable media rail, collapsed tool calls revealed with Ctrl-O, and less jank on long conversations and session reloads Update to version 0.41.0: * Add experimental tower mode for multi-agent orchestration and Remote Control for reaching a local web session remotely * Add the WaitFor tool so the agent can wait for a background task inside the current turn, and an optional fork parameter that starts a subagent from a snapshot of the caller's history * Support two OAuth login methods, kimi.ai and kimi.com, and activate several skills in one prompt * Enable the subagent model pool in every launch mode by default and make turn-level file history unconditional * Add a dangerous-command guard that always asks before shutdown, reboot or rm -rf in manual and YOLO permission modes, disabled with [permission] dangerous_command_guard; auto mode never blocks * Remove kimi web --allow-remote-terminals; PTY terminal routes are served on loopback binds only * Require Edit and Write to read a file first, and reject a write when the file changed on disk since that read * Rework the bundled web dashboard: multi-tab right sidebar, Open/Done/Workspaces session tabs, a plugin marketplace panel and mobile bottom sheets * ... see upstream's release notes for the full list - Vendor the runtime dependencies upstream stopped inlining in 0.39.0: * Add ws, qrcode and qrcode's own pngjs and dijkstrajs as sources, installed into the package's private node_modules * Unpack the npm tarball directly instead of running npm install, which would resolve the new dependencies against the registry and pull in qrcode's CLI-only yargs tree * Declare the vendored trees with Provides: bundled(...) - CVE-2026-48779: ws denial of service from a high volume of tiny WebSocket fragments; the ws inlined in the old bundle predated the 8.21.0 fix, the vendored ws is 8.21.3 (boo#1268927) - CVE-2026-45736: ws uninitialized memory disclosure via websocket.close() with a TypedArray, fixed by the same ws version (boo#1269951) - Load the compiled node-pty addon during the build check as well

Affected software

Affected versions
>=8.0.0 <8.20.1Red HatRed Hat Hardened Imagesaarch64dotnet9-0-main@aarch64>= 8.0.0, < 8.20.1SUSEkimi-code-0.42.0-bp160.1.1.aarch64x86_64kimi-code-0.42.0-bp160.1.1.x86_64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/10/2026, 20:13:46 UTC

Technical Analysis

The ws library for Node.js, versions 8.0.0 up to but not including 8.20.1, contains a vulnerability in the websocket.close() implementation. When a TypedArray is passed as the reason argument, uninitialized memory may be disclosed, potentially leaking sensitive information. This is due to the use of uninitialized resources (CWE-908). The issue was fixed in version 8.20.1. Red Hat has acknowledged the vulnerability and identified affected products, but no specific fix for Red Hat Hardened Images RPMs has been released yet. The CVSS v3.1 base score is 4.4 (medium severity) with network attack vector, high confidentiality impact, and requires high privileges.

Potential Impact

Successful exploitation of this vulnerability can lead to disclosure of sensitive information from uninitialized memory in the ws WebSocket library. There is no impact on integrity or availability. The vulnerability requires high privileges to exploit and no user interaction. Red Hat products using this library may be affected if they permit passing a TypedArray to websocket.close(). No known exploits are reported in the wild.

Mitigation Recommendations

A fix is available in ws version 8.20.1. Users and vendors should upgrade to this version or later to remediate the vulnerability. Red Hat has not yet released a specific fix for affected Hardened Images RPMs but is investigating. Until a fix is released, users should avoid passing TypedArray objects as the reason argument to websocket.close() or apply vendor-specific mitigations if available. Monitor Red Hat advisories for updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:27171
Cve Count
1
State
PUBLISHED

Threat ID: 6a359317f198dc38c106106d

Added to database: 06/19/2026, 19:05:59 UTC

Last enriched: 08/10/2026, 20:13:46 UTC

Last updated: 09/17/2026, 18:13:32 UTC

Views: 104

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses