kimi-cli (deprecated)

Disable date: 2027-01-17

Install command:
brew install kimi-cli

CLI agent for MoonshotAI Kimi platform

https://moonshotai.github.io/kimi-cli/

License: Apache-2.0

Development: Pull requests

Formula JSON API: /api/formula/kimi-cli.json

Formula code: kimi-cli.rb on GitHub

Bottle (binary package) installation support provided for:

macOS on
Apple Silicon
golden gate ✅
tahoe ✅
sequoia ✅
sonoma ✅
macOS on
Intel
sonoma ✅
Linux ARM64 ✅
x86_64 ✅

Current versions:

stable ✅ 1.48.0
head ⚡️ HEAD

Revision: 1

Depends on:

certifi 2026.7.22 Mozilla CA bundle for Python
cryptography 50.0.2 Cryptographic recipes and primitives for Python
libyaml 0.2.5 YAML Parser
pillow 12.3.0 Friendly PIL fork (Python Imaging Library)
pydantic 2.13.5 Data validation using Python type hints
python@3.14 3.14.8 Interpreted, interactive, object-oriented programming language
re2 2025-11-05 Alternative to backtracking PCRE-style regular expression engines
rpds-py 2026.9.1 Python bindings to Rust's persistent data structures

Depends on when building from source:

pkgconf 3.0.7 Package compiler and linker metadata toolkit
pybind11 3.1.0 Seamless operability between C++11 and Python
rust 1.99.0 Safe, concurrent, practical language

Uses from macOS: libffi, libxml2 (since macOS Ventura), libxslt

Binaries: kimi, kimi-cli

Known vulnerabilities in the current version:

GHSA-59cr-6r3x-644w GitPython submodule update path traversal can write outside the repository
GHSA-2gx3-rcp4-g85q (medium) PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete...
GHSA-42vr-xj54-vc7v (medium) PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_sign...
GHSA-8wjv-2p76-3863 (medium) PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
GHSA-9j54-fg26-wv3r (high) PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
GHSA-9v7f-9g4p-ffgj (high) PyJWT: PyJWKClient follows redirects when fetching JWKS
GHSA-ffc3-869f-jxw9 (critical) PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/as...
GHSA-hxm8-2xgr-2p9m (medium) PyJWT: Non-canonical signature segments enable raw-token revocation bypass
GHSA-jwrc-g2q2-pq5p (medium) PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
GHSA-p4g4-x82p-q773 (high) PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
GHSA-r6x4-923q-g947 (high) PyJWT BOM Bypass
GHSA-w2cx-738m-mc7w (high) PyJWT accepts public JWK containers as HMAC secrets
GHSA-w6j9-cwv2-h6wq (medium) PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
GHSA-x33g-cr3x-6449 (medium) PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion
GHSA-gvp8-978c-rx2q (medium) PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on d...
GHSA-54p9-h82j-f925 (medium) Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction
GHSA-w2fm-2cpv-w7v5 aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
GHSA-hcc4-c3v8-rx92 AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
GHSA-2vrm-gr82-f7m5 AIOHTTP has CRLF injection through multipart part content type header construction
GHSA-p998-jp59-783m AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler o...
GHSA-m5qp-6w8w-w647 (high) AIOHTTP has a Multipart Header Size Bypass
GHSA-3wq7-rqq7-wx6j AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
GHSA-966j-vmvw-g2g9 (medium) AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
GHSA-mwh4-6h8g-pg8w AIOHTTP has HTTP response splitting via \r in reason phrase
GHSA-63hf-3vf5-4wqf (critical) AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values -...
GHSA-c427-h43c-vf67 AIOHTTP accepts duplicate Host headers
GHSA-jg22-mg44-37j8 (medium) AIOHTTP is Vulnerable to Deserialization of Untrusted Data
GHSA-vfmq-68hx-4jfw (high) lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
GHSA-hg6j-4rv6-33pg AIOHTTP is vulnerable to cross-origin redirect with per-request cookies
GHSA-4jhm-jv67-739f (high) `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
GHSA-m6qw-4cw2-hm4m aiohttp: CRLF injection in multipart headers
GHSA-4fvr-rgm6-gqmc aiohttp: HTTP/1 Pipelined Requests Queue Without Limit
GHSA-xcgm-r5h9-7989 aiohttp: Incomplete websocket frame payloads bypass memory limits
GHSA-4m7w-qmgq-4wj5 aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections
GHSA-hpj7-wq8m-9hgp aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges
GHSA-63hw-fmq6-xxg2 aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines
GHSA-g3cq-j2xw-wf74 aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup
GHSA-2fqr-mr3j-6wp8 aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence
GHSA-9x8q-7h8h-wcw9 aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect
GHSA-qr67-gv47-xwwh (medium) asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the inten...
GHSA-2wxc-x7rj-hg8f (high) asyncssh has SCP Path Traversal to Arbitrary File Write
GHSA-mq44-7p77-q5h7 AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate
GHSA-rw4j-r22c-9gc3 (medium) AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MSG_CHANNEL_OPEN / OPE...
GHSA-3rp5-jjmw-4wv2 (high) GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand...
GHSA-mfx4-hv73-q22v AIOHTTP: HTTP request smuggling via WebSocket upgrade
GHSA-cq5v-8q36-5273 AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)
GHSA-539m-9xh6-q6rr (medium) GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, ...
GHSA-3f7w-8rr8-f37f (high) GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enab...
GHSA-p538-c434-8v24 (medium) GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Co...
GHSA-94p4-4cq8-9g67 (high) GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incompl...
GHSA-6p8h-3wgx-97gf (high) GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary comma...
GHSA-fjr4-x663-mwxc (high) GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (ke...
GHSA-r9mr-m37c-5fr3 (high) GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enable...
GHSA-hh9p-6wh2-4mfc (medium) GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
GHSA-9rj7-rf2p-w77r (high) GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via -...
GHSA-4gmw-gg2m-w46p (high) GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enab...
GHSA-wvpp-8hx9-p66j (high) GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token ...
GHSA-jm78-9fvv-mhgr (high) GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling ...
GHSA-hmq2-w58f-27jc (high) GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules...
PYSEC-2026-3785 (high) GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodul...
PYSEC-2026-3786 (critical) GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g....
PYSEC-2026-3787 (high) GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling a...
PYSEC-2026-3788 (medium) GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrar...
GHSA-3wxw-xv34-2frg (medium) GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling a...
PYSEC-2026-3982 (high) GitPython: Repository content can impersonate the git directory, leading to arbitrary code execution
PYSEC-2026-3984 (high) GitPython: Denial of Service via catastrophic backtracking (ReDoS) in Actor.name_email_regex — co...
GHSA-8988-9cw3-xx77 urllib3: HTTPS proxy TLS configuration may be ignored or overridden
GHSA-gh4c-6fx4-qh6g urllib3: Chunked Deflate streaming can enter an infinite loop
GHSA-vxq7-64xx-v4gw urllib3: HTTPResponse.stream()/read_chunked() buffers an unbounded chunk-size line into memory

Data from Homebrew/advisory-database. Run brew vulns kimi-cli for a live check.

Analytics:

30 days90 days365 days
Installs154368,758
Installs (--HEAD)017
Installs on Request154368,756
Installs on Request (--HEAD)017
Build Errors0