Kagi VRP — Subdomain Takeover Proof of Concept

This page is served from sidekick-ui-next.kagi.com, a dangling Kagi subdomain (CNAME → kagi-sidekick-ui-next.pages.dev pointing at a deleted Cloudflare Pages project).

It was claimed as authorized security research under the Kagi Bug Bounty Program to demonstrate the takeover. It contains no malicious content and will be released as soon as the DNS record is corrected.

Reported to: security@kagi.com
PoC token: KAGI-VRP-TAKEOVER-09dae4391d38c79f
Date: 2026-05-20