PT-2026-106752 · Microsoft · Microsoft.Openapi.Kiota.Builder+1
CVE-2026-105795
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft.OpenApi.Kiota versions 1.25.1 through 1.34.1
Microsoft.OpenApi.Kiota.Builder versions 1.25.1 through 1.34.1
Description
Kiota, an OpenAPI based HTTP Client code generator, fails to validate the
x-ai-capabilities.response semantics.oauth card path variable when copying it from an OpenAPI description into a generated API plugin manifest. An attacker can provide parent-directory traversal, rooted paths, or absolute URIs instead of a safe package-relative file reference. While Kiota does not execute code or read local files during generation, the unsafe reference is propagated into the manifest. A consuming host that resolves this reference may cross the intended plugin-package boundary or utilize an unintended authentication card.Recommendations
Upgrade Microsoft.OpenApi.Kiota to version 1.35.0 or later and regenerate affected plugin manifests.
Upgrade Microsoft.OpenApi.Kiota.Builder to version 1.35.0 or later and regenerate affected plugin manifests.
Generate plugins only from trusted, integrity-protected OpenAPI descriptions.
Review generated manifests before packaging or deployment and remove any
oauth card path that is not a safe relative reference confined to the plugin package.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microsoft.Openapi.Kiota
Microsoft.Openapi.Kiota.Builder