Feed/CVE-2026-59864
CVE-2026-59864CRITICALCVSS 0.0

CVE-2026-59864

Published Jul 16, 2026·Updated Aug 17, 2026

NVD Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot and Teams plugin manifests without path validation, allowing ../, absolute, rooted, UNC, Windows drive, or URI paths in response_semantics.static_template.file to cause path traversal or out-of-package file inclusion when the generated plugin was deployed. This issue is fixed in version 1.32.5.

Affected Packages (2)

Microsoft.OpenApi.Kiota.BuilderNUGET
From 1.30.0
Fixed in 1.32.5
Microsoft.OpenApi.KiotaNUGET
From 1.30.0
Fixed in 1.32.5

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free