{"id":"CVE-2026-79294","published":"2026-09-18T14:18:48.077","lastModified":"2026-09-22T20:00:03.713","description":"Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbitrary code via the HTML artifact Preview rendering; public Share view component","cvssScore":6.1,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"http://kimi.com","tags":[]},{"url":"http://moonshot.com","tags":[]},{"url":"https://github.com/MGTx2/CVE-2026-79294/blob/main/README.md","tags":[]},{"url":"https://kimi.com/share/","tags":[]},{"url":"https://github.com/MGTx2/CVE-2026-79294/blob/main/README.md","tags":[]}],"exploitRefs":[{"url":"https://github.com/MGTx2/CVE-2026-79294/blob/main/README.md","tags":[]},{"url":"https://github.com/MGTx2/CVE-2026-79294/blob/main/README.md","tags":[]}],"hasPoc":true,"ai":null}