CVE-2026-59863High▾ TwilightMicrosoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
1.1%
1.1% → 1.4%
Microsoft Kiota honors a poisoned .kiota/workspace.json — the workspace configuration that Kiota's
documented team workflow has developers commit to their repository — unvalidated on
kiota client generate / kiota plugin generate. A repository (or pull request) containing a malicious
per-client / per-plugin outputPath causes Kiota, when a developer or CI runs the documented regenerate
command, to (CWE-22) write the entire generated client to an arbitrary path outside the workspace — the
outputPath was not confined to the workspace root and absolute paths were accepted.
Confirmed on Kiota 1.32.4 (KIOTA_CONFIG_PREVIEW=true, the self-contained linux-x64 release binary).
// .kiota/workspace.json (committed to the repo)
"clients": { "MyClient": {
"outputPath": "/abs/path/outside/repo/pwned_client" // -> generated client written here (CWE-22)
}}
Running kiota client generate --client-name MyClient in the repo writes MyClient.cs,
P/PRequestBuilder.cs, … to the attacker-chosen outputPath (verified outside the working tree).
descriptionLocationThe per-consumer descriptionLocation is intentionally fetched at generation time — this is how Kiota knows
where to pull an updated description from when refreshing a client, the same way any other value in a
committed lock/config file is honored. It is not treated as a vulnerability and is unchanged; only
outputPath is now confined.
A malicious or compromised repository — or a malicious PR that edits .kiota/workspace.json — leads to
arbitrary file write on the developer's or CI host's filesystem (overwrite source/build files, drop files in
auto-loaded locations) whenever a teammate clones/pulls and runs the documented kiota client generate /
kiota plugin generate to refresh the client. CWE-22.
This is a different trust boundary from the OpenAPI-description-based findings: the malicious input is the Kiota config, not the spec.
Fixed in 1.32.5 (https://github.com/microsoft/kiota/pull/7885). On loading a workspace configuration,
each client/plugin outputPath is validated to be a relative subdirectory of the workspace: null/empty,
rooted paths (POSIX /, UNC \\ / //, Windows drive X:\), and any .. traversal segment are rejected,
and the resolved full path must stay under the workspace root. Generation aborts with an error if any
consumer's outputPath escapes the workspace.
Upgrade to Kiota 1.32.5 or later. Review any committed workspace configs for outputPath values that
point outside the workspace.
Microsoft.OpenApi.Kiota < 1.32.5Microsoft.OpenApi.Kiota.Builder < 1.32.5Upgrade to a patched release:
Microsoft.OpenApi.Kiota 1.32.5Microsoft.OpenApi.Kiota.Builder 1.32.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59867High· 7.1Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVE-2026-59864CriticalMicrosoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
CVE-2026-59865CriticalMicrosoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
CVE-2026-59866HighMicrosoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
GHSA-p5rm-jg5c-8c77MediumMicrosoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
CVE-2021-27065High· 7.8Microsoft Exchange Server Remote Code Execution Vulnerability