Kimi client patches arbitrary-command vulnerability via local embedded server
KimiDevs · x · 2026-09-24
KimiDevs shipped a round of client fixes, headlined by a security patch:
- Security: fixed a vulnerability letting malicious web pages run arbitrary commands through the local embedded server
- Stability: long conversations freezing on open, streaming stutter, and excessive mobile memory use
- Agents: subagent model showing unconfigured and not applying; endless spinner after deleting a session; task notification cards losing stream order; Swarm card display issues
- Polish: full-width rounded Markdown tables, readable cron job details, deduped address-bar suggestions, full Bash command in the expanded tool panel
More from coding & agent
- Creator apologizes after AI agent auto-posted at 2am; revokes unsupervised posting permissions — LinusEkenstam · 2026-09-24
- Lovable launches Chats, detailing the agent architecture behind ~500M daily events — AlexandrePesant · 2026-09-24
- Xiaomi's MiMo V2.6 Pro builds a habit tracker in 62 seconds for under 5 cents — socialwithaayan · 2026-09-24
- Two engineers with AI shipped 3 finance infra projects in one quarter—after fixing what made agents guess — alex_verem · 2026-09-24
- How do you count an agent call blocked by an output guardrail? Real metering question — Rama_Surasani_ · 2026-09-24
- Brokerage MCP Postmortem: 4 Pitfalls Making Trader Leaderboards Safe for Agents — Accomplished_Fun_408 · 2026-09-24