Command Injection Vulnerability in Kiota by Microsoft
CVE-2026-59865
9.3CRITICAL
What is CVE-2026-59865?
Kiota, an OpenAPI based HTTP client code generator from Microsoft, has a command injection vulnerability due to improper handling of the command-line input sourced from OpenAPI specifications. Versions prior to 1.32.5 are susceptible, allowing an attacker to manipulate the installation command suggested by the tool. If a crafted or compromised OpenAPI description is processed, this may lead to the execution of malicious commands when users run the suggested command either manually or via the Kiota VS Code extension. This vulnerability has been addressed in version 1.32.5.
Affected Version(s)
kiota < 1.32.5