3.1
CVE-2026-105795
- EPSS 1.21%
- Veröffentlicht 06.10.2026 14:19:03
- Zuletzt bearbeitet 06.10.2026 18:16:47
- Erkennungen
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests
Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a consuming host that resolves the reference, allowing the host to cross the intended plugin-package boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code merely while generating the manifest, and impact requires downstream resolution of the unsafe reference. This issue is fixed in version 1.35.0.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellermicrosoft
≫
Produkt
kiota
Version
>= 1.25.1, < 1.35.0
Status
affected
Herstellermicrosoft
≫
Produkt
Microsoft.OpenApi.Kiota
Version
>= 1.25.1, < 1.35.0
Status
affected
Herstellermicrosoft
≫
Produkt
Microsoft.OpenApi.Kiota.Builder
Version
>= 1.25.1, < 1.35.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.21% | 0.676 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 3.1 | 1.6 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
|
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
https://github.com/microsoft/kiota/security/advisories/GHSA-6gw6-rv2g-25mg
https://github.com/microsoft/kiota/pull/8055
https://github.com/microsoft/kiota/commit/fc0f219b8a665c4c69be8befcff035ba0eb8e4ce
https://github.com/microsoft/kiota/releases/tag/v1.35.0