Security fixes are provided for the latest published release.
Use GitHub private vulnerability reporting. Please do not open a public issue for an undisclosed vulnerability.
Do not include real Kimi Code logs, prompts, source code, API keys, configuration files, usernames, or absolute personal paths. Create a minimal reproduction with synthetic data whenever possible.
The application is designed to be local-only and read-only. Reports involving unexpected network access, sensitive-data exposure, filesystem writes, unsafe path handling, or unbounded resource use are especially useful.