Command Injection Vulnerability in Kiota by Microsoft
CVE-2026-59865

9.3CRITICAL

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-59865?

Kiota, an OpenAPI based HTTP client code generator from Microsoft, has a command injection vulnerability due to improper handling of the command-line input sourced from OpenAPI specifications. Versions prior to 1.32.5 are susceptible, allowing an attacker to manipulate the installation command suggested by the tool. If a crafted or compromised OpenAPI description is processed, this may lead to the execution of malicious commands when users run the suggested command either manually or via the Kiota VS Code extension. This vulnerability has been addressed in version 1.32.5.

Affected Version(s)

kiota < 1.32.5

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.