Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a consuming host that resolves the reference, allowing the host to cross the intended plugin-package boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code merely while generating the manifest, and impact requires downstream resolution of the unsafe reference. This issue is fixed in version 1.35.0.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6gw6-rv2g-25mg | Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a consuming host that resolves the reference, allowing the host to cross the intended plugin-package boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code merely while generating the manifest, and impact requires downstream resolution of the unsafe reference. This issue is fixed in version 1.35.0. | |
| Title | Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T14:19:03.186Z
Reserved: 2026-10-05T20:37:19.364Z
Link: CVE-2026-105795
No data.
Status : Awaiting Analysis
Published: 2026-10-06T15:17:16.437
Modified: 2026-10-06T16:00:36.547
Link: CVE-2026-105795
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA