Blind SSRF via Aliyun OSS Image Processing + Content-Type Upload Bypass
Bug Bounty Report: Blind SSRF via Aliyun OSS Image Processing + Content-Type Upload Bypass Reported to: security@moonshot.cn (or appropriate channel) Date: 2026-06-26 Reporter: FrankSx Severity: High (Blind SSRF to Internal Cloud Infrastructure + File Upload Bypass) 1. Executive Summary Two related vulnerabilities were identified in Kimi's file upload and CDN serving infrastructure: Content-Type Upload Bypass: The /apiv2/slides:upload endpoint accepts arbitrary file types as long as the Content-Type header is declared as an image type (e.g., image/svg+xml , image/png ). This allows uploading non-image files (PDFs, HTML, scripts, etc.) that are then served from the CDN with the declared image type. Blind SSRF via Aliyun OSS Image Processing: User-uploaded files on kimi-img.moonshot.cn are stored in Aliyun OSS. The CDN URLs accept arbitrary x-oss-process query parameters, including the image/watermark operation. This operation fetches an attacker-controlled URL server-s...