Executive brief
Microsoft Kiota is a tool used by developers to generate software code for interacting with web services. A security flaw allowed malicious web service descriptions to trick the tool into recommending and potentially automatically running harmful commands on a developer's computer. This could lead to a complete takeover of the developer's workstation or automated build systems if they use the Kiota command-line tool or its VS Code extension with a compromised service definition.
Technical details
A command injection vulnerability exists in Microsoft Kiota due to improper handling of the 'x-ms-kiota-info' extension in OpenAPI descriptions. The 'kiota info' command and the associated VS Code extension would read the 'dependencyInstallCommand' field from an untrusted OpenAPI spec and present or execute it as a trusted recommendation. An attacker can provide a crafted OpenAPI description containing malicious shell commands in this field. When a developer runs 'kiota info' or uses the IDE extension to install dependencies, the attacker-controlled command is executed with the privileges of the user. The fix in version 1.32.5 removes support for spec-supplied install commands entirely.
Affected products
- Microsoft Microsoft.OpenApi.Kiota < 1.32.5
- Microsoft Microsoft.OpenApi.Kiota.Builder < 1.32.5
Timeline
- 2026-07-03: disclosed: Initial disclosure to Microsoft
- 2026-07-16: advisory: NVD publication date
- 2026-07-24: patched: GitHub Advisory published and fix confirmed in 1.32.5