Sploitus

CVE-2026-25046

No indexed exploits for CVE-2026-25046 yet

Kimi Agent SDK is a set of libraries that expose the Kimi Code (Kimi CLI) agent runtime in applications. The vsix-publish.js and ovsx-publish.js scripts pass filenames to execSync() as shell command strings. Prior to version 0.1.6, filenames containing shell metacharacters like $(cmd) could execute arbitrary commands. Note: This vulnerability exists only in the repository's development scripts. The published VSCode extension does not include these files and end users are not affected. This is fixed in version 0.1.6 by replacing execSync with execFileSync using array arguments. As a workaround, ensure .vsix files in the project directory have safe filenames before running publish scripts.

Affected products
Kimi-Agent-Sdk, Vscode
Fix
Available
CVSS 3.1
2.9 LOW
EPSS
0.1% (2th percentile)
Weakness
CWE-77
NVD status
Deferred
Published
2026-01-29
CVE-2026-25046 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-25046 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-25046 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.