HTTP Client Code Generator Vulnerability in Kiota by Microsoft
CVE-2026-59867
7.1HIGH
What is CVE-2026-59867?
The Kiota HTTP Client code generator has a vulnerability that allows the resolution of OpenAPI $ref values by fetching remote HTTP(s) URLs and reading local file paths. This security flaw can be exploited using attacker-controlled OpenAPI descriptions, leading to build-time SSRF, remote file inclusion, and local file inclusion. The issue has been addressed in versions 1.29.1 and 1.32.5 by introducing the AllowedExternalOriginsStreamLoader and the --allowed-external-origins option to mitigate the risk of such attacks.
Affected Version(s)
kiota >= 1.30.0, < 1.31.1 < 1.30.0, 1.31.1
kiota < 1.29.1 < 1.29.1