PT-2026-60490 · Kiota · Kiota

CVE-2026-59865

·

Published

2026-07-16

·

Updated

2026-08-17

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kiota versions prior to 1.29.1 Kiota versions prior to 1.32.5
Description Kiota, an OpenAPI based HTTP Client code generator, contains an issue where the kiota info command reads the x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand value, along with dependency name and version values, directly from an OpenAPI description. The tool then presents this spec-supplied command as its own recommended installation instruction. An attacker providing a compromised or malicious OpenAPI description can inject arbitrary shell commands into these fields. If a developer manually executes the suggested command or uses the Kiota VS Code extension's kiota info --json flow, it can lead to command injection and remote code execution (RCE) on the workstation or CI host.
Recommendations Update Kiota to version 1.29.1 or later. Update Kiota to version 1.32.5 or later. Update the Kiota VS Code extension to a version built against 1.32.5 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59865
GHSA-HQ9Q-27G5-QWPJ

Affected Products

Kiota