VYPR

kimi-code

by MoonshotAI

CVEs (1)

  • CVE-2026-17534Jul 27, 2026
    risk 0.00cvss epss 0.00

    Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for…