Sceawere

Vulnerability Detail

CVE-2026-105795UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kiota Path Traversal Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.1
Creation Date
10h ago
Vendor
microsoft
Product
kiota
Attack Type
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a consuming host that resolves the reference, allowing the host to cross the intended plugin-package boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code merely while generating the manifest, and impact requires downstream resolution of the unsafe reference. This issue is fixed in version 1.35.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.1",
  "pubDate": "2026-10-06T15:17:16.437Z",
  "pubdate": "2026-10-06T15:17:16.437Z",
  "executiveSummary": "Kiota is susceptible to an arbitrary path traversal vulnerability stemming from the improper validation of the 'x-ai-capabilities.response_semantics.oauth_card_path' field within OpenAPI descriptions.\nThis vulnerability allows an attacker to inject malicious path references—such as directory traversal sequences, rooted paths, or absolute URIs—into generated API plugin manifests.\nWhile Kiota itself does not execute code during generation, the inclusion of these unchecked references poses a critical risk to downstream systems that parse and resolve the manifest.\nImpact includes the ability for an attacker to force a host to access files outside the intended plugin-package boundary or to substitute legitimate authentication cards with malicious ones.\nThe vulnerability affects Kiota versions 1.25.1 through 1.34.0 (inclusive).\nRemediation requires updating the Kiota generator to version 1.35.0 or later, where input validation for this field has been implemented.",
  "technicalDetails": "The vulnerability exists within the Kiota OpenAPI-based HTTP client code generation engine. During the generation of API plugin manifests, Kiota extracts the 'x-ai-capabilities.response_semantics.oauth_card_path' property from the provided OpenAPI description and embeds it directly into the output manifest.\nThe root cause is a failure to sanitize or validate this specific property against expected patterns. The generator assumes the provided value is a safe, relative file reference; however, it lacks the logic to enforce this constraint or to reject malicious input.\nAn attacker can exploit this by crafting a malicious OpenAPI document containing directory traversal sequences (e.g., '../'), absolute system paths, or malicious URI schemes within the 'oauth_card_path' field. Because the generator does not validate this data, the malicious string is persisted in the generated manifest.\nThe attack flow proceeds as follows: 1) An attacker provides a compromised or malicious OpenAPI description to the Kiota generator. 2) Kiota generates an API plugin manifest that includes the malicious path reference. 3) A downstream host or consumer application reads the generated manifest. 4) The downstream host attempts to resolve the malicious path reference, resulting in the host accessing resources outside the intended sandbox boundary or processing a rogue authentication card.\nThis represents a 'confused deputy' type of scenario where the generator acts as the entry point for malicious configuration data, and the downstream consumer acts as the execution point, inadvertently processing the malicious path when resolving the authentication card requirements.\nBecause the generator does not perform local file system operations or execute code during the generation phase, the vulnerability is latent until the manifest is utilized by a host system. No specific authentication or privilege requirements are needed to trigger the generation of the malformed manifest, as it relies on the attacker's ability to supply the input OpenAPI file.\nSuccessful exploitation depends entirely on the downstream host's resolution logic; if the consuming environment follows the traversal or URI instructions, the attacker can achieve unauthorized file access or authentication bypass/manipulation depending on the specific host architecture and security controls."
}
CVE-2026-105795: Kiota Path Traversal Vulnerability (LOW Severity, CVSS: 3.1) | Sceawere