| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-p5rm-jg5c-8c77 | Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass) |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 17 Aug 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft kiota |
|
| Vendors & Products |
Microsoft
Microsoft kiota |
Mon, 17 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI). When the generated manifest is deployed and consumed by an AI host, this can lead to inclusion or disclosure of files outside the intended package boundary. This vulnerability is fixed in 1.29.1 and 1.34.0. | |
| Title | Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass) | |
| Weaknesses | CWE-22 CWE-829 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T15:26:40.140Z
Reserved: 2026-08-13T17:44:28.644Z
Link: CVE-2026-73851
Updated: 2026-08-17T15:26:33.630Z
Status : Received
Published: 2026-08-17T15:16:57.980
Modified: 2026-08-17T16:17:47.677
Link: CVE-2026-73851
No data.
OpenCVE Enrichment
Updated: 2026-08-17T18:00:05Z
Github GHSA