Path Traversal Vulnerability in Kiota OpenAPI HTTP Client by Microsoft
CVE-2026-59864
9.3CRITICAL
What is CVE-2026-59864?
The Kiota OpenAPI based HTTP Client code generator had a vulnerability in versions prior to 1.32.5, allowing unvalidated input to cause path traversal or out-of-package file inclusion in the generated plugin manifests for Microsoft 365 Copilot and Teams. When using the commands kiota plugin add and kiota plugin generate with the -t APIPlugin option, attacker-controlled values could be emitted from x-ai-adaptive-card and x-ai-capabilities into the response semantics, potentially exposing sensitive files and compromising the application's security. This issue has been resolved in version 1.32.5.
Affected Version(s)
kiota < 1.32.5