Path Traversal Vulnerability in Kiota OpenAPI Client Code Generator
CVE-2026-105795

3.1LOW

What is CVE-2026-105795?

A vulnerability in Kiota, the OpenAPI based HTTP Client code generator, allows for potential path traversal exploits. Versions prior to 1.35.0 do not validate the 'x-ai-capabilities.response_semantics.oauth_card_path' field from attacker-controlled OpenAPI descriptions, leading to unsafe file references being injected into generated API plugin manifests. This lack of validation can enable access to unintended plugin functionalities or escalate authentication card usage, posing risks to the consuming host. Safe practices recommend upgrading to version 1.35.0, where this vulnerability has been addressed.

Affected Version(s)

kiota >= 1.25.1, < 1.35.0

Microsoft.OpenApi.Kiota >= 1.25.1, < 1.35.0

Microsoft.OpenApi.Kiota.Builder >= 1.25.1, < 1.35.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.