PT-2026-60491 · Kiota · Kiota

CVE-2026-59866

·

Published

2026-07-16

·

Updated

2026-08-17

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Kiota versions prior to 1.29.1 Kiota versions prior to 1.32.5
Description Kiota fails to sanitize clientClassName and clientNamespaceName values from the x-ms-kiota-info extension when the kiota generate command is executed without the -c/--class-name flag. This allows an attacker who controls or compromises an OpenAPI description to perform a path traversal attack, writing generated source files to locations outside the designated -o output directory. Additionally, the lack of sanitization enables the injection of arbitrary text into the generated class or namespace declarations, which can lead to build corruption and denial of service by preventing the generated code from compiling.
Recommendations Update Kiota to version 1.29.1 or later. Update Kiota to version 1.32.5 or later.

Exploit

Fix

Path traversal

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59866
GHSA-4VV7-JJ25-4GH6

Affected Products

Kiota