PT-2026-106752 · Microsoft · Microsoft.Openapi.Kiota.Builder+1

CVE-2026-105795

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Microsoft.OpenApi.Kiota versions 1.25.1 through 1.34.1 Microsoft.OpenApi.Kiota.Builder versions 1.25.1 through 1.34.1
Description Kiota, an OpenAPI based HTTP Client code generator, fails to validate the x-ai-capabilities.response semantics.oauth card path variable when copying it from an OpenAPI description into a generated API plugin manifest. An attacker can provide parent-directory traversal, rooted paths, or absolute URIs instead of a safe package-relative file reference. While Kiota does not execute code or read local files during generation, the unsafe reference is propagated into the manifest. A consuming host that resolves this reference may cross the intended plugin-package boundary or utilize an unintended authentication card.
Recommendations Upgrade Microsoft.OpenApi.Kiota to version 1.35.0 or later and regenerate affected plugin manifests. Upgrade Microsoft.OpenApi.Kiota.Builder to version 1.35.0 or later and regenerate affected plugin manifests. Generate plugins only from trusted, integrity-protected OpenAPI descriptions. Review generated manifests before packaging or deployment and remove any oauth card path that is not a safe relative reference confined to the plugin package.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105795
GHSA-6GW6-RV2G-25MG

Affected Products

Microsoft.Openapi.Kiota
Microsoft.Openapi.Kiota.Builder