CVE-2026-25046General

LOWCVSS 2.9 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publish.js and ovsx-publish.js scripts pass filenames to execSync() as shell command strings. Prior to version 0.1.6, filenames containing shell metacharacters like $(cmd) could execute arbitrary commands. Note: This vulnerability exists only in the repository's development scripts. The published VSCode extension does not include these files and end users are not affected. This is fixed in version 0.1.6 by replacing execSync with execFileSync using array arguments. As a workaround, ensure .vsix files in the project directory have safe filenames before running publish scripts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-01-29); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-29: 1Mentions · 2026-01-30: 1Mentions · 2026-03-03: 1Technical Details · 2026-01-30: 1Technical Details · 2026-03-03: 101-2901-3003-03
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-291
General1
2026-01-301
Disclosure1
2026-03-031
General1
Full discourse3 posts
  • シンギュラリティ研究所🐒@guava_asi
    General

    guard-scanner v5.0.6 🛡️ + CVE-2026-2256 (MS-Agent check_safe bypass) + CVE-2026-25046 (Kimi execSync injection) 150 patterns / 139 tests / 0.016ms http://github.com/koatora20/guard-scanner #AIAgentSecurity #CVE

    Post summary

    The post lists two CVEs with brief descriptors and links to a scanner tool, but provides no exploit, patch, or active exploitation details.

    00000104
    15 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25046 Command Injection Vulnerability in Kimi Agent SDK Development Scripts Before 0.1.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25046

    Post summary

    A command injection vulnerability (CVE-2026-25046) in Kimi Agent SDK Development Scripts versions prior to 0.1.6 is disclosed, but no PoC, exploit code, patch, or exploitation evidence is provided.

    0000086
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-25046 Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publish.js and ovsx-publish.js scripts pass filename… https://www.cve.org/CVERecord?id=CVE-2026-25046

    Post summary

    The text briefly references CVE-2026-25046 and a set of scripts involved, offering no further details about exploitation, patches, or technical nature.

    00000364
    56.5K followersView on X

Explore more