๐Ÿ” CVE Alert

CVE-2026-105795

LOW 3.1

Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests

CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th

Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a consuming host that resolves the reference, allowing the host to cross the intended plugin-package boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code merely while generating the manifest, and impact requires downstream resolution of the unsafe reference. This issue is fixed in version 1.35.0.

CWE CWE-22
Vendor microsoft
Product kiota
Ecosystems
Industries
TechnologyEnterprise
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for microsoft kiota

Be the first to know when new low vulnerabilities affecting microsoft kiota are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

microsoft / kiota
>= 1.25.1, < 1.35.0
microsoft / Microsoft.OpenApi.Kiota
>= 1.25.1, < 1.35.0
microsoft / Microsoft.OpenApi.Kiota.Builder
>= 1.25.1, < 1.35.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/microsoft/kiota/security/advisories/GHSA-6gw6-rv2g-25mg github.com: https://github.com/microsoft/kiota/pull/8055 github.com: https://github.com/microsoft/kiota/commit/fc0f219b8a665c4c69be8befcff035ba0eb8e4ce github.com: https://github.com/microsoft/kiota/releases/tag/v1.35.0