CVE-2026-25046 | MoonshotAI kimi-agent-sdk up to 0.1.5 vsix-publish.js execSync command injection (GHSA-mv58-gxx5-8hj3 / EUVD-2026-4948)
A vulnerability identified as critical has been detected in MoonshotAI kimi-agent-sdk up to 0.1.5. This issue affects the function execSync of the file vsix-publish.js. The manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2026-25046. Local access is required to approach this attack. No exploit exists.
You should upgrade the affected component.