{"id":"CVE-2026-17534","summary":"Kimi Code FetchURL SSRF protection bypass via DNS-resolving hostnames and redirects","details":"Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for example via prompt injection) can supply a crafted public hostname that resolves to loopback or another internal address, or a public URL that redirects to such a target, and thereby reach internal network services that the denylist was intended to block. FetchURL is included in the default auto-approve tool set, so the call does not require interactive user confirmation in manual mode.","modified":"2026-07-29T03:30:25.151488164Z","published":"2026-07-27T09:19:23.982Z","database_specific":{"cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17534.json","cna_assigner":"JFROG"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17534.json"},{"type":"ADVISORY","url":"https://github.com/MoonshotAI/kimi-code/releases/tag/%40moonshot-ai%2Fkimi-code%400.27.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-17534"},{"type":"FIX","url":"https://github.com/MoonshotAI/kimi-code/commit/31449728b72df94e22bcb2de350a1e7624895e30"},{"type":"FIX","url":"https://github.com/MoonshotAI/kimi-code/pull/1791"},{"type":"PACKAGE","url":"git://github.com/MoonshotAI/kimi-code"},{"type":"PACKAGE","url":"https://github.com/MoonshotAI/kimi-code"}],"affected":[{"ranges":[{"type":"GIT","repo":"git://github.com/moonshotai/kimi-code","events":[{"introduced":"0"},{"fixed":"5cc194956f6f9752d172aa4994385d2d2e7a066f"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.27.0"}],"source":"AFFECTED_FIELD"}},{"type":"GIT","repo":"https://github.com/moonshotai/kimi-code","events":[{"introduced":"0"},{"fixed":"5cc194956f6f9752d172aa4994385d2d2e7a066f"},{"fixed":"31449728b72df94e22bcb2de350a1e7624895e30"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.27.0"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["@moonshot-ai/kimi-code@0.26.0","@moonshot-ai/kimi-code@0.25.0","@moonshot-ai/kimi-code@0.24.2","@moonshot-ai/kimi-code@0.24.1","@moonshot-ai/kimi-code@0.24.0","@moonshot-ai/kimi-code@0.23.6","@moonshot-ai/kimi-code@0.23.5","@moonshot-ai/kimi-code@0.23.4","@moonshot-ai/kimi-code@0.23.3","@moonshot-ai/kimi-code@0.23.2","@moonshot-ai/kimi-code@0.23.1","@moonshot-ai/kimi-code@0.23.0","@moonshot-ai/kimi-code@0.22.3","@moonshot-ai/kimi-code@0.22.2","@moonshot-ai/kimi-code@0.22.1","@moonshot-ai/kimi-code@0.22.0","@moonshot-ai/kimi-code@0.21.1","@moonshot-ai/kimi-code@0.21.0","@moonshot-ai/kimi-code@0.20.3","@moonshot-ai/kimi-code@0.20.2","@moonshot-ai/kimi-code@0.20.1","@moonshot-ai/kimi-code@0.20.0","@moonshot-ai/kimi-code@0.19.2","@moonshot-ai/kimi-code@0.19.1","@moonshot-ai/kimi-code@0.19.0","@moonshot-ai/kimi-code@0.18.0","@moonshot-ai/kimi-code@0.17.1","@moonshot-ai/kimi-code@0.17.0","@moonshot-ai/kimi-code@0.16.0","@moonshot-ai/kimi-code@0.15.0","@moonshot-ai/kimi-code@0.14.3","@moonshot-ai/kimi-code@0.14.2","@moonshot-ai/kimi-code@0.14.1","@moonshot-ai/kimi-code@0.14.0","@moonshot-ai/kimi-code@0.13.1","@moonshot-ai/kimi-code@0.13.0","@moonshot-ai/kimi-code@0.12.1","@moonshot-ai/kimi-code@0.12.0","@moonshot-ai/kimi-code@0.11.0","@moonshot-ai/kimi-code@0.10.1","@moonshot-ai/kimi-code@0.10.0","@moonshot-ai/kimi-code@0.9.0","@moonshot-ai/kimi-code@0.8.0","@moonshot-ai/kimi-code@0.7.0","@moonshot-ai/kimi-code@0.6.0","@moonshot-ai/kimi-code@0.5.0","@moonshot-ai/kimi-code@0.4.0","@moonshot-ai/kimi-code@0.3.0","@moonshot-ai/kimi-code@0.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17534.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N"}]}