Junglewise Threat Intelligence

CVE-2026-17534: MoonshotAI Kimi Code SSRF bypass in FetchURL tool

CVE-2026-17534 · Severity: medium · CVSS 5.5 · Published 2026-07-27

Executive brief

Kimi Code is a tool used by developers to build and run AI agents. A security flaw in its URL fetching tool allowed the AI to be tricked into accessing private internal network services or local files on the developer's machine. This could lead to the exposure of sensitive internal data or cloud credentials if an attacker uses techniques like prompt injection to manipulate the AI's behavior.

Technical details

Kimi Code (specifically the @moonshot-ai/kimi-code package) prior to version 0.27.0 implemented SSRF protections using only a static denylist of hostnames and IP literals in the assertSafeFetchTarget function. This implementation failed to resolve DNS hostnames before validation and did not re-validate targets following HTTP redirects. An attacker can bypass these protections via DNS rebinding, crafted public domains that resolve to internal IP ranges (e.g., loopback or RFC1918), or by using a public URL that redirects to an internal service. Because FetchURL is part of the default auto-approve toolset, these requests can be triggered without user intervention via prompt injection. The vulnerability is fixed in version 0.27.0 by implementing DNS resolution before validation, manual redirect following with per-hop re-validation, and connection pinning to prevent TOCTOU/DNS-rebinding attacks.

Affected products

  • MoonshotAI Kimi Code (@moonshot-ai/kimi-code) < 0.27.0

Timeline

  • 2026-07-16: disclosed: Pull request submitted to harden FetchURL SSRF protections
  • 2026-07-17: patched: Fix merged and version 0.27.0 released
  • 2026-07-27: advisory: CVE-2026-17534 published

References

Related threats