PT-2026-60490 · Kiota · Kiota
CVE-2026-59865
·
Published
2026-07-16
·
Updated
2026-08-17
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kiota versions prior to 1.29.1
Kiota versions prior to 1.32.5
Description
Kiota, an OpenAPI based HTTP Client code generator, contains an issue where the
kiota info command reads the x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand value, along with dependency name and version values, directly from an OpenAPI description. The tool then presents this spec-supplied command as its own recommended installation instruction. An attacker providing a compromised or malicious OpenAPI description can inject arbitrary shell commands into these fields. If a developer manually executes the suggested command or uses the Kiota VS Code extension's kiota info --json flow, it can lead to command injection and remote code execution (RCE) on the workstation or CI host.Recommendations
Update Kiota to version 1.29.1 or later.
Update Kiota to version 1.32.5 or later.
Update the Kiota VS Code extension to a version built against 1.32.5 or later.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kiota