Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-17534: Kimi Code SSRF via DNS resolution bypass

Kimi Code before version 0.27.0 has a Server-Side Request Forgery (SSRF) vulnerability in its FetchURL function that can be exploited via prompt injection. An attacker can bypass the hostname denylist by using crafted public hostnames that resolve to internal addresses or URLs that redirect to internal targets.

Disclosed 27 July 2026 · Record updated 13 September 2026

Impact

Attackers can reach internal network services through SSRF via prompt injection attacks on the default auto-approve FetchURL tool.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-17534