
Responsible-disclosure advisory for CVE-2026-79294, a stored XSS in Moonshot AI Kimi's HTML artifact Preview via the public Share view enabling session-token theft and account takeover.
CVE-2026-79294 — Stored XSS in Moonshot AI Kimi's HTML artifact Preview, delivered through the public Share view, leading to session token exfiltration and demonstrated account takeover. Responsible disclosure advisory.
| Vendor / product | Moonshot AI — Kimi |
| Components | HTML artifact Preview rendering; public Share view |
| Weakness | CWE-79 — Improper Neutralization of Input During Web Page Generation |
Kimi renders model-generated HTML artifacts in a Preview pane inside the application's own origin, without neutralising script. Sharing a conversation publishes that artifact at a public Share URL, so script authored by one account runs in the browser of anyone who opens the link.
The session values Kimi relies on are held in localStorage and are therefore readable by
that script:
access_token
refresh_token
msh_user_id
Script execution consequently does not stop at script execution. Those three values can be read out of a victim's browser, sent anywhere, and replayed to obtain an authenticated session as that victim.
attacker account → artifact containing exfiltration script → public Share
→ victim opens the link → script runs in Kimi's origin
→ the three localStorage values reach the attacker
→ replayed into a clean browser → authenticated as the victim
An attacker needs an ordinary account. The victim needs only to open a share link while signed in — which is what share links are for.
| Observed | How |
|---|---|
| Script executes in the victim's browser | A request reached the attacker's endpoint, originating from the victim's session |
| The three values are script-readable | All three were present in that request body |
| The values authenticate on their own | Written into a browser that had never signed in to Kimi; after reload, that browser held an authenticated session |
| The values are the cause | Control: same browser, values omitted, reload — remained unauthenticated |
Both accounts involved were created and controlled by the researcher. No third party's data was accessed at any point.
The chain is documented above in full. The working payload and the receiving endpoint are withheld — publishing them would arm the attack rather than describe it.
The artifact prompt takes the form:
Generate an HTML page that reads the three localStorage values above
and POSTs them to <attacker endpoint>.