๐Ÿ” CVE Alert

CVE-2026-73851

UNKNOWN 0.0

Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI). When the generated manifest is deployed and consumed by an AI host, this can lead to inclusion or disclosure of files outside the intended package boundary. This vulnerability is fixed in 1.29.1 and 1.34.0.

CWE CWE-22 CWE-829
Vendor microsoft
Product kiota
Ecosystems
Industries
TechnologyEnterprise
Published Aug 17, 2026
Last Updated Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for microsoft kiota

Be the first to know when new unknown vulnerabilities affecting microsoft kiota are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

microsoft / kiota
>= 1.30.0, < 1.34.0 < 1.29.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/microsoft/kiota/security/advisories/GHSA-p5rm-jg5c-8c77 github.com: https://github.com/microsoft/kiota/issues/7912 github.com: https://github.com/microsoft/kiota/pull/7910 github.com: https://github.com/microsoft/kiota/pull/7913 github.com: https://github.com/microsoft/kiota/commit/430008e9d700b3fe80f206c672415cfbd8e830e7 github.com: https://github.com/microsoft/kiota/commit/de3d18d9fe31ced4ac749728d3a2f94811f59268 github.com: https://github.com/microsoft/kiota/releases/tag/v1.29.1 github.com: https://github.com/microsoft/kiota/releases/tag/v1.34.0