A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or encode HTML/JavaScript payloads generated by the AI model. When a user switches to the 'Preview' tab to view AI-generated code, the malicious payload is rendered directly into the DOM, leading to arbitrary JavaScript execution in the victim's browser session.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/MGTx2 |
|
| https://github.com/MGTx2/CVE-2026-39107 |
|
History
Wed, 03 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Kimi AI v1.0 Web Interface Cross‑Site Scripting via Preview Feature | |
| Weaknesses | CWE-79 |
Wed, 03 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or encode HTML/JavaScript payloads generated by the AI model. When a user switches to the 'Preview' tab to view AI-generated code, the malicious payload is rendered directly into the DOM, leading to arbitrary JavaScript execution in the victim's browser session. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-03T17:54:55.865Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-39107
No data.
Status : Received
Published: 2026-06-03T18:16:23.377
Modified: 2026-06-03T18:16:23.377
Link: CVE-2026-39107
No data.
OpenCVE Enrichment
Updated: 2026-06-03T18:30:36Z
Weaknesses