CVE-2026-95660

Summary

A security flaw has been discovered in Moonshot AI Kimi Code up to 0.31.0. The affected element is an unknown function of the file agent-core-v2/src/agent/mcp/config-loader.ts of the component MCP Configuration Loader. The manipulation results in os command injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. Upgrading to version 0.31.1 is sufficient to fix this issue. It is recommended to upgrade the affected component. Beyond the trust prompt, the fix resolves fd/stty binaries to absolute paths specifically "so untrusted workspaces cannot plant bare-name executables before confirmation," fixing a secondary $PATH path-planting vector alongside the primary untrusted-.mcp.json auto-spawn.

Affected Software

VendorProductVersion RangeStatus
Moonshot AIKimi Code0.1affected
Moonshot AIKimi Code0.2affected
Moonshot AIKimi Code0.3affected
Moonshot AIKimi Code0.4affected
Moonshot AIKimi Code0.5affected
Moonshot AIKimi Code0.6affected
Moonshot AIKimi Code0.7affected
Moonshot AIKimi Code0.8affected
Moonshot AIKimi Code0.9affected
Moonshot AIKimi Code0.10affected
Moonshot AIKimi Code0.11affected
Moonshot AIKimi Code0.12affected
Moonshot AIKimi Code0.13affected
Moonshot AIKimi Code0.14affected
Moonshot AIKimi Code0.15affected
Moonshot AIKimi Code0.16affected
Moonshot AIKimi Code0.17affected
Moonshot AIKimi Code0.18affected
Moonshot AIKimi Code0.19affected
Moonshot AIKimi Code0.20affected
Moonshot AIKimi Code0.21affected
Moonshot AIKimi Code0.22affected
Moonshot AIKimi Code0.23affected
Moonshot AIKimi Code0.24affected
Moonshot AIKimi Code0.25affected
Moonshot AIKimi Code0.26affected
Moonshot AIKimi Code0.27affected
Moonshot AIKimi Code0.28affected
Moonshot AIKimi Code0.29affected
Moonshot AIKimi Code0.30affected
Moonshot AIKimi Code0.31.0affected
Moonshot AIKimi Code0.31.1unaffected

Weaknesses

  • CWE-78: OS Command Injection
  • CWE-77: Command Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References