File Inclusion Vulnerability in Kiota HTTP Client by Microsoft
CVE-2026-73851
6.1MEDIUM
What is CVE-2026-73851?
Kiota, an OpenAPI-based HTTP Client code generator, is vulnerable to a file inclusion issue where an attacker can manipulate the OpenAPI description. If exploited, this allows the attacker to reference files outside the designated manifest package, potentially leading to the disclosure of sensitive information such as system files. This issue was resolved in versions 1.29.1 and 1.34.0 to prevent such unauthorized file access.
Affected Version(s)
kiota >= 1.30.0, < 1.34.0 < 1.30.0, 1.34.0
kiota < 1.29.1 < 1.29.1