CVE-2026-73851
Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI). When the generated manifest is deployed and consumed by an AI host, this can lead to inclusion or disclosure of files outside the intended package boundary. This vulnerability is fixed in 1.29.1 and 1.34.0.
| CWE | CWE-22 CWE-829 |
| Vendor | microsoft |
| Product | kiota |
| Ecosystems | |
| Industries | TechnologyEnterprise |
| Published | Aug 17, 2026 |
| Last Updated | Aug 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for microsoft kiota
Be the first to know when new unknown vulnerabilities affecting microsoft kiota are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
microsoft / kiota
>= 1.30.0, < 1.34.0 < 1.29.1
References
github.com: https://github.com/microsoft/kiota/security/advisories/GHSA-p5rm-jg5c-8c77 github.com: https://github.com/microsoft/kiota/issues/7912 github.com: https://github.com/microsoft/kiota/pull/7910 github.com: https://github.com/microsoft/kiota/pull/7913 github.com: https://github.com/microsoft/kiota/commit/430008e9d700b3fe80f206c672415cfbd8e830e7 github.com: https://github.com/microsoft/kiota/commit/de3d18d9fe31ced4ac749728d3a2f94811f59268 github.com: https://github.com/microsoft/kiota/releases/tag/v1.29.1 github.com: https://github.com/microsoft/kiota/releases/tag/v1.34.0