Executive brief
Microsoft Kiota is a code generator used to create AI plugins for Microsoft 365 Copilot and Teams. The tool fails to validate file paths embedded in OpenAPI specifications, allowing attackers to inject path traversal sequences (such as `../`) into generated plugin manifests. When a malicious or compromised OpenAPI description is processed, Kiota writes unsanitized paths directly into the manifest file that the AI host later resolves, potentially exposing files outside the plugin package or loading unauthorized content.
Technical details
The vulnerability is a path traversal (CWE-22) / out-of-package file inclusion (CWE-829) in Kiota's `PluginsGenerationService`. When processing OpenAPI `x-ai-adaptive-card` and `x-ai-capabilities` extensions, Kiota writes the `static_template.file` field verbatim into the generated Copilot/Teams plugin manifest without sanitization. An attacker can craft a malicious OpenAPI specification with traversal sequences like `../../../../../../etc/passwd` or absolute paths; these are copied unchanged into the manifest's `response_semantics.static_template.file`. The vulnerability is not exploitable at build time on the developer's machine, but rather manifests downstream when the generated plugin is deployed to an AI host (Microsoft 365 Copilot or Teams), which resolves the file path relative to the plugin package, allowing out-of-package file references. The attack requires that an attacker control or compromise the OpenAPI description used as input to Kiota. Patches are available in versions 1.29.1 and 1.32.5, which validate file paths to reject absolute URIs, rooted/UNC paths, Windows drive paths, and `..` traversal segments.
Affected products
- Microsoft OpenAPI Kiota < 1.29.1, >= 1.30.0 and < 1.32.5
- Microsoft OpenAPI Kiota Builder < 1.29.1, >= 1.30.0 and < 1.32.5
Timeline
- 2026-07-24: disclosed: GitHub Advisory GHSA-4jwf-m4wg-8p66 published
- 2026-07-24: patched: Patches released: versions 1.29.1 and 1.32.5