Tools AI Risk Radar ai-incident-0052
Incident record
Kimi K3 finds a Redis zero-day and writes a working exploit
- Severity
- Critical
- Status
- Proof-of-concept
- Type
- AI-Found Vuln
- Target
- Redis
- Actor
- researcher
- CVE
- CVE-2026-25589
What happened
Security researcher Chaofan Shou directed Moonshot AI's open-weight Kimi K3 model to audit Redis, and reported that it found a previously unknown memory-safety flaw in stream consumer groups and wrote working remote-code-execution exploits for four versions in 27 minutes using 32 agents. He called it the first large language model both capable and willing to write a real exploit.
The flaw is a double-free that survived an earlier patch, so servers marked as fixed stayed exploitable. Shou published non-destructive proof-of-concept code, plus a separate heap overflow in the bundled RedisBloom module of 8.8.0.
Sources
- YFarmX reportyfarmx.com/kimi-k3-redis-zero-day-exploit/
- Chaofan Shou (X)x.com/Fried_rice/status/2080059356322918777
- berabuddies/redis-poc (GitHub)github.com/berabuddies/redis-poc
On YFarmX
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026