Microsoft.OpenApi.Kiota.Builder
OpenAPI based HTTP Client code generator
Activity
- Latest release
- 1w ago
- Total releases
- 75
- Cadence
- ~20 days
- Last 12 months
- 15
Reach
- Stars
- 3.8k
Details
- License
- MIT
- First release
- May 30, 2022
| Version | Released | |
|---|---|---|
1.35.0
minor
|
1.35.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.29.1
patch
|
1.29.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.34.1
patch
|
1.34.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.34.0
minor
|
1.34.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.33.0
minor
|
1.33.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.32.5
patch
|
1.32.5
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.32.4
patch
5 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.32.4
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.32.3
patch
6 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.32.3
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.32.2
patch
7 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.32.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.32.1
patch
7 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.32.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.32.0
minor
7 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.32.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.31.1
patch
9 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.31.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
1.31.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.31.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
1.30.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.30.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.29.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.29.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.28.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.28.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.27.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.27.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.26.1
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.26.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.26.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.26.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.25.1
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.25.1
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.24.3
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.24.3
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.24.2
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.24.2
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.24.1
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.24.1
patch
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.24.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.24.0
minor
Dependencies (9)
+ 1 more
Changelog
Compare changes
|
|
1.23.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.23.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.22.3
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.22.3
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.22.2
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.22.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.22.1
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.22.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.22.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.22.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.21.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.21.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.20.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.20.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.19.1
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.19.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.19.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.19.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.18.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.18.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.17.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.17.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.16.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.16.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.15.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.15.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.14.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.14.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.13.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.13.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.12.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.12.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.11.1
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.11.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.11.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.11.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.10.1
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.10.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.10.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.10.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.9.1
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.9.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.9.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.9.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.8.2
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.8.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.8.1
patch
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.8.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.8.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.8.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.0
minor
10 CVEs
CVE-2026-59866
GHSA-4vv7-jj25-4gh6
Jul 24, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
Network
Low
None
SummaryMicrosoft Kiota emitted the
Confirmed on Kiota 1.32.4 (the self-contained Details
ImpactA developer or CI host generating a client from an attacker-controlled or compromised OpenAPI description
(without This does not reach clean remote code execution: because PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7884). RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later and regenerate affected clients. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59865
GHSA-hq9q-27g5-qwpj
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
Network
Low
None
None
Summary
A developer who followed kiota's explicit instruction (run the suggested install command) executed
attacker-controlled shell — command injection → RCE. The IDE-facing Confirmed on Kiota 1.32.4. Details
Without ImpactA developer who ran Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE). PatchesFixed in 1.29.1 and 1.32.5 (https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied
RemediationUpgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+. Affected versions
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
+ 34 more Show less
1.1.3
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.2.0
1.2.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
Fixed in
1.29.1
1.32.5
References
Updated Aug 17, 2026 · Source: OSV.dev
CVE-2026-59863
GHSA-4rj6-vrwv-wr8m
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
Network
Low
None
SummaryMicrosoft Kiota honors a poisoned Confirmed on Kiota 1.32.4 ( Details
Running Note on
|
1.7.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|