Path Traversal Vulnerability in Kiota OpenAPI HTTP Client by Microsoft
CVE-2026-59864

9.3CRITICAL

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-59864?

The Kiota OpenAPI based HTTP Client code generator had a vulnerability in versions prior to 1.32.5, allowing unvalidated input to cause path traversal or out-of-package file inclusion in the generated plugin manifests for Microsoft 365 Copilot and Teams. When using the commands kiota plugin add and kiota plugin generate with the -t APIPlugin option, attacker-controlled values could be emitted from x-ai-adaptive-card and x-ai-capabilities into the response semantics, potentially exposing sensitive files and compromising the application's security. This issue has been resolved in version 1.32.5.

Affected Version(s)

kiota < 1.32.5

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.