CVE-2026-95660 | Moonshot AI Kimi Code up to 0.31.0 MCP Configuration Loader config-loader.ts os command injection
A vulnerability was found in Moonshot AI Kimi Code up to 0.31.0. It has been declared as critical. The affected element is an unknown function of the file agent-core-v2/src/agent/mcp/config-loader.ts of the component MCP Configuration Loader. The manipulation results in os command injection.
This vulnerability is cataloged as CVE-2026-95660. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
Beyond the trust prompt, the fix resolves fd/stty binaries to absolute paths specifically “so untrusted workspaces cannot plant bare-name executables before confirmation,” fixing a secondary $PATH path-planting vector alongside the primary untrusted-.mcp.json auto-spawn.VulDB Recent EntriesRead More