Back Heise.De Kimi K3: Chinese AI finds several zero-day vulnerabilities in redis database
The developers of the open-source in-memory database redis have released updated versions that close several vulnerabilities within it. They thus confirm security vulnerabilities that an IT researcher found with the Chinese AI Kimi K3. This is in competition with the current top models from OpenAI and Anthropic and thus now proves that it can actually detect vulnerabilities.
The user “Chaofan Shou” posted on X that he found a total of 19 zero-day vulnerabilities in the then-current version 8.8.0 of the redis database in 90 minutes using the AI from the Chinese start-up Moonshot AI. Kimi K3 also created proof-of-concept code (PoC) to demonstrate the exploitation of the vulnerabilities. Shou has published a GitHub repository with the PoCs .
On Friday night, the redis project has now released several updated versions that patch at least parts of the presented security holes. redis 8.8.1, 8.6.5, 8.4.5, 8.2.8, 7.4.10, 7.2.15 and 6.2.23 fix several of the vulnerabilities. The developers thus confirm the security vulnerabilities, for example, for the exploit “P88W” from the vulnerability repository.
An assessment of the severity of the vulnerabilities, as well as CVE vulnerability entries, are currently still missing. However, the available proof-of-concept code makes it easier for attackers to exploit the security holes. IT managers should therefore promptly update to the updated redis version of their deployed development branch. Source code is available, and Linux distributions are likely to provide updates in the software management shortly.
The Kimi-K3 AI from Moonshot AI is experiencing high demand. The provider has temporarily stopped new subscriptions due to GPU bottlenecks. The proof that Kimi K3 detects vulnerabilities and generates exploit code is likely to further increase interest in it. This has so far been the domain of, for example, Anthropic's Mythos or Fable or OpenAI's Codex Security .
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
