Executive brief
Moonshot AI Kimi is an AI assistant platform that allows users to create and share conversations and content artifacts. A cross-site scripting (XSS) vulnerability in the HTML artifact preview and public share view allows an attacker to inject malicious code that executes in a victim's browser, potentially leading to data theft, session hijacking, or unauthorized actions performed on behalf of the user.
Technical details
The vulnerability is a reflected or stored cross-site scripting (XSS) flaw in the HTML artifact preview rendering component of Moonshot AI Kimi. The vulnerable component fails to properly sanitize or encode HTML content when rendering artifacts in the public share view. An attacker can craft a malicious artifact containing JavaScript payload that executes in the browser of any user viewing the shared artifact, without requiring authentication. The attack vector is network-based and requires only that a victim click a malicious link or visit a shared artifact URL. No patch information is currently available in the advisory.
Affected products
- Moonshot AI Kimi as of 2026-07-18
Timeline
- 2026-09-18: disclosed