PT-2026-60489 · Microsoft · Kiota
CVE-2026-59864
·
Published
2026-07-16
·
Updated
2026-08-17
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kiota versions prior to 1.29.1
Kiota versions prior to 1.32.5
Description
Kiota, an OpenAPI based HTTP Client code generator, fails to validate paths provided in the
x-ai-adaptive-card and x-ai-capabilities extensions when using the kiota plugin add and kiota plugin generate (with -t APIPlugin) commands. This allows an attacker to embed malicious values—such as absolute paths, UNC paths, Windows drive paths, URIs, or directory traversal sequences (../)—into the static template.file field within the response semantics of the generated Microsoft 365 Copilot and Teams plugin manifests. When the generated plugin is deployed to an AI host, these values can lead to path traversal or out-of-package file inclusion, where the host resolves the file reference outside of the intended plugin package.Recommendations
Update Kiota to version 1.29.1 or later and regenerate affected plugins.
Update Kiota to version 1.32.5 or later and regenerate affected plugins.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kiota