Researcher Says Kimi K3 Agents Found 19 Redis Zero-Days in 90 Minutes and Built a Working RCE in 27 — Redis Has Already Shipped Patches
Security researcher Chaofan Shou reported on X that agents driven by Moonshot's Kimi K3 surfaced 19 Redis zero-days in roughly 90 minutes, with a separate run producing a working Redis 8.8.0 remote-code-execution exploit in 27 minutes. The findings span stock builds of Redis 6.2.22, 7.4.9, 8.6.4 and 8.8.0, chaining a stream consumer-group shared-NACK double-free (tracked as CVE-2026-25589) with a heap overflow in the bundled RedisBloom TDigest module. Neither Redis maintainers nor Moonshot have independently confirmed the agent-attribution claim — but Redis shipped fixes across 6.2.23, 7.2.15, 7.4.10, 8.2.8, 8.4.5, 8.6.5 and 8.8.1, which corroborates that the bugs themselves are real. If the timing holds up, it is the sharpest public data point yet on autonomous vulnerability discovery moving from demo to production tooling.
↳ Follow the thread