Junglewise Threat Intelligence

CVE-2026-59865: Microsoft Kiota command injection in kiota info via OpenAPI extension

CVE-2026-59865 · Severity: critical · CVSS 4 · Published 2026-07-16

Technologies: Microsoft.OpenApi.Kiota.Builder, Microsoft.OpenApi.Kiota, Microsoft Kiota. Vendors: Microsoft.

Executive brief

Microsoft Kiota is a tool used by developers to generate software code for interacting with web services. A security flaw allowed malicious web service descriptions to trick the tool into recommending and potentially automatically running harmful commands on a developer's computer. This could lead to a complete takeover of the developer's workstation or automated build systems if they use the Kiota command-line tool or its VS Code extension with a compromised service definition.

Technical details

A command injection vulnerability exists in Microsoft Kiota due to improper handling of the 'x-ms-kiota-info' extension in OpenAPI descriptions. The 'kiota info' command and the associated VS Code extension would read the 'dependencyInstallCommand' field from an untrusted OpenAPI spec and present or execute it as a trusted recommendation. An attacker can provide a crafted OpenAPI description containing malicious shell commands in this field. When a developer runs 'kiota info' or uses the IDE extension to install dependencies, the attacker-controlled command is executed with the privileges of the user. The fix in version 1.32.5 removes support for spec-supplied install commands entirely.

Affected products

  • Microsoft Microsoft.OpenApi.Kiota < 1.32.5
  • Microsoft Microsoft.OpenApi.Kiota.Builder < 1.32.5

Timeline

  • 2026-07-03: disclosed: Initial disclosure to Microsoft
  • 2026-07-16: advisory: NVD publication date
  • 2026-07-24: patched: GitHub Advisory published and fix confirmed in 1.32.5

References

Related threats