Executive brief
Microsoft Kiota, a tool used by developers to generate API clients, contains a vulnerability that allows a malicious project configuration to write files to unintended locations on a user's computer. If a developer or automated system runs the tool on a repository containing a poisoned configuration file, an attacker could overwrite critical system or project files. This could lead to unauthorized code execution or the compromise of build environments.
Technical details
A path traversal vulnerability (CWE-22) exists in Microsoft Kiota versions prior to 1.32.5. The tool fails to validate the 'outputPath' parameter within the '.kiota/workspace.json' configuration file, which is often committed to version control. An attacker can provide an absolute path or use traversal segments (e.g., '../') to force the tool to write generated API client files to arbitrary locations on the host filesystem when 'kiota client generate' or 'kiota plugin generate' is executed. This requires user interaction, such as a developer or CI/CD pipeline processing a malicious repository or pull request. The fix introduces validation to ensure the output path remains a relative subdirectory of the workspace root.
Affected products
- Microsoft Microsoft.OpenApi.Kiota < 1.32.5
- Microsoft Microsoft.OpenApi.Kiota.Builder < 1.32.5
Timeline
- 2026-07-03: disclosed: Initial disclosure in microsoft/kiota repository
- 2026-07-16: advisory: NVD publication date
- 2026-07-24: advisory: GitHub Advisory Database publication date
- 2026-07-24: patched: Fixed in version 1.32.5