Description
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`) emitted attacker-controlled static_template.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot and Teams plugin manifests without path validation, allowing ../, absolute, rooted, UNC, Windows drive, or URI paths in response_semantics.static_template.file to cause path traversal or out-of-package file inclusion when the generated plugin was deployed. This issue is fixed in version 1.32.5.
Severity (CVSS)
| Base score | 9.3 |
|---|---|
| Severity | Critical |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-22 — CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-829 — CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Affected products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | kiota | < 1.32.5 |
References
- https://github.com/microsoft/kiota/security/advisories/GHSA-4jwf-m4wg-8p66 (x_refsource_CONFIRM)
- https://github.com/microsoft/kiota/pull/7892 (x_refsource_MISC)
- https://github.com/microsoft/kiota/commit/9a185994a4e549b7bba3cc2beffb9736aa902e79 (x_refsource_MISC)
- https://github.com/microsoft/kiota/releases/tag/v1.32.5 (x_refsource_MISC)
Generated from the official CVE List on 17 Jul 2026 07:01 UTC.