Configuration Vulnerability in Kiota Product by Microsoft
CVE-2026-59863
7HIGH
What is CVE-2026-59863?
Kiota, an OpenAPI-based HTTP Client code generator, had a vulnerability that allowed a poisoned workspace configuration to bypass validation for outputPath values. This vulnerability could be exploited through malicious repositories or pull requests, enabling attackers to write generated client files outside the intended workspace root on developer or CI hosts. The issue has been addressed in versions 1.29.1 and 1.32.5 of Kiota.
Affected Version(s)
kiota >= 1.30.0, < 1.31.1 < 1.30.0, 1.31.1
kiota < 1.29.1 < 1.29.1