Junglewise Threat Intelligence

CVE-2026-95660: Moonshot AI Kimi Code arbitrary command injection in MCP configuration loader

CVE-2026-95660 · Severity: medium · CVSS 6.3 · Published 2026-09-22

Executive brief

Moonshot AI Kimi Code is a development environment that automatically loads Model Context Protocol (MCP) configurations from project files. An attacker can craft a malicious .mcp.json file in a project directory that executes arbitrary OS commands when a user opens the project, without any explicit user action or confirmation beyond opening the workspace. This allows code execution with the same privileges as the user running Kimi Code.

Technical details

The vulnerability is an OS command injection in the MCP Configuration Loader component (agent-core-v2/src/agent/mcp/config-loader.ts) triggered by auto-execution of untrusted .mcp.json files from the project directory. The attack requires the victim to open a malicious project but does not require any user interaction beyond that. The fix resolves fd/stty binary names to absolute paths to prevent $PATH planting attacks that allow injecting executables before the actual commands are invoked.

Affected products

  • Moonshot AI Kimi Code up to 0.31.0

Timeline

  • 2026-09-22: disclosed
  • 2026-07-31: patched: Version 0.31.1 released

References

Related threats