PT-2026-60491 · Kiota · Kiota
CVE-2026-59866
·
Published
2026-07-16
·
Updated
2026-08-17
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Kiota versions prior to 1.29.1
Kiota versions prior to 1.32.5
Description
Kiota fails to sanitize
clientClassName and clientNamespaceName values from the x-ms-kiota-info extension when the kiota generate command is executed without the -c/--class-name flag. This allows an attacker who controls or compromises an OpenAPI description to perform a path traversal attack, writing generated source files to locations outside the designated -o output directory. Additionally, the lack of sanitization enables the injection of arbitrary text into the generated class or namespace declarations, which can lead to build corruption and denial of service by preventing the generated code from compiling.Recommendations
Update Kiota to version 1.29.1 or later.
Update Kiota to version 1.32.5 or later.
Exploit
Fix
Path traversal
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Kiota