Path Traversal Vulnerability in Kiota OpenAPI Client Code Generator
CVE-2026-105795
3.1LOW
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 6 October 2026
What is CVE-2026-105795?
A vulnerability in Kiota, the OpenAPI based HTTP Client code generator, allows for potential path traversal exploits. Versions prior to 1.35.0 do not validate the 'x-ai-capabilities.response_semantics.oauth_card_path' field from attacker-controlled OpenAPI descriptions, leading to unsafe file references being injected into generated API plugin manifests. This lack of validation can enable access to unintended plugin functionalities or escalate authentication card usage, posing risks to the consuming host. Safe practices recommend upgrading to version 1.35.0, where this vulnerability has been addressed.
Affected Version(s)
kiota >= 1.25.1, < 1.35.0
Microsoft.OpenApi.Kiota >= 1.25.1, < 1.35.0
Microsoft.OpenApi.Kiota.Builder >= 1.25.1, < 1.35.0