PT-2026-60492 · Kiota · Kiota

CVE-2026-59867

·

Published

2026-07-16

·

Updated

2026-08-17

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Kiota versions prior to 1.32.5
Description Kiota resolves OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths. When using kiota generate with an attacker-controlled or influenced description, this can lead to build-time Server-Side Request Forgery (SSRF), remote file inclusion, and local file inclusion by inlining external schemas into generated clients.
Recommendations Update to version 1.32.5 or later. Use the --allowed-external-origins option to restrict external origins.

Exploit

Fix

Path traversal

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59867
GHSA-RG4H-FPCP-2QM8

Affected Products

Kiota