Configuration Vulnerability in Kiota Product by Microsoft
CVE-2026-59863

7HIGH

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-59863?

Kiota, an OpenAPI-based HTTP Client code generator, had a vulnerability that allowed a poisoned workspace configuration to bypass validation for outputPath values. This vulnerability could be exploited through malicious repositories or pull requests, enabling attackers to write generated client files outside the intended workspace root on developer or CI hosts. The issue has been addressed in versions 1.29.1 and 1.32.5 of Kiota.

Affected Version(s)

kiota >= 1.30.0, < 1.31.1 < 1.30.0, 1.31.1

kiota < 1.29.1 < 1.29.1

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.