Feed/CVE-2026-59865
CVE-2026-59865CRITICALCVSS 0.0

CVE-2026-59865

Published Jul 16, 2026·Updated Aug 17, 2026

NVD Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install command, allowing an attacker-controlled or compromised description to cause command injection when the suggested command was run manually or through the Kiota VS Code extension's kiota info --json dependency-install flow. This issue is fixed in version 1.32.5.

Affected Packages (2)

Microsoft.OpenApi.Kiota.BuilderNUGET
From 1.30.0
Fixed in 1.32.5
Microsoft.OpenApi.KiotaNUGET
From 1.30.0
Fixed in 1.32.5

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free