YFarmX logoYFarmX

Tools AI Risk Radar ai-incident-0052

Incident record

Kimi K3 finds a Redis zero-day and writes a working exploit

Severity
Critical
Status
Proof-of-concept
Type
AI-Found Vuln
Target
Redis
Actor
researcher
CVE
CVE-2026-25589

What happened

Security researcher Chaofan Shou directed Moonshot AI's open-weight Kimi K3 model to audit Redis, and reported that it found a previously unknown memory-safety flaw in stream consumer groups and wrote working remote-code-execution exploits for four versions in 27 minutes using 32 agents. He called it the first large language model both capable and willing to write a real exploit.

The flaw is a double-free that survived an earlier patch, so servers marked as fixed stayed exploitable. Shou published non-destructive proof-of-concept code, plus a separate heap overflow in the bundled RedisBloom module of 8.8.0.

Sources

One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026