Feed/CVE-2026-59863
CVE-2026-59863HIGHCVSS 0.0

CVE-2026-59863

Published Jul 16, 2026·Updated Aug 17, 2026

NVD Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a malicious repository or pull request to use absolute paths, rooted POSIX / paths, UNC \\ or // paths, Windows drive X:\ paths, or .. traversal segments to write generated client files outside the workspace root on a developer or CI host. This issue is fixed in version 1.32.5.

Affected Packages (2)

Microsoft.OpenApi.Kiota.BuilderNUGET
From 1.30.0
Fixed in 1.32.5
Microsoft.OpenApi.KiotaNUGET
From 1.30.0
Fixed in 1.32.5

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free