Junglewise Threat Intelligence

CVE-2026-59867: Microsoft Kiota SSRF and File Inclusion via OpenAPI external references

CVE-2026-59867 · Severity: high · CVSS 7.1 · Published 2026-07-16

Technologies: Microsoft.OpenApi.Kiota.Builder, Microsoft.OpenApi.Kiota, Microsoft Kiota. Vendors: Microsoft.

Executive brief

Microsoft Kiota is a tool used by developers to generate software code from API descriptions. A vulnerability in how it handles external references allows an attacker to trick the tool into reading sensitive local files or making unauthorized network requests during the code generation process. This could lead to the exposure of internal company data or cloud credentials if the tool is run on a malicious API specification.

Technical details

Microsoft Kiota (prior to version 1.32.5) fails to restrict the resolution of '$ref' pointers within OpenAPI descriptions. An attacker can provide a malicious specification that uses these pointers to trigger Server-Side Request Forgery (SSRF) against internal network resources or Local File Inclusion (LFI) to read arbitrary files from the build host. The contents of these external resources are then inlined into the generated client code. While output escaping prevents direct Remote Code Execution (RCE), the vulnerability allows for significant data exfiltration from developer machines or CI/CD environments. The fix introduces a default-deny policy for external references, requiring explicit opt-in via the '--allowed-external-origins' parameter.

Affected products

  • Microsoft Microsoft.OpenApi.Kiota < 1.32.5
  • Microsoft Microsoft.OpenApi.Kiota.Builder < 1.32.5

Timeline

  • 2026-07-03: disclosed
  • 2026-07-16: advisory: NVD publication date
  • 2026-07-24: patched: GitHub Advisory published/reviewed

References

Related threats