CVE-2026-105795: Unvalidated Custom Extension Path Traversal in Microsoft Kiota
Vulnerability ID: CVE-2026-105795
CVSS Score: 3.1
Published: 2026-10-06
CVE-2026-105795 (GHSA-6gw6-rv2g-25mg) is a critical path traversal vulnerability in Microsoft Kiota, an OpenAPI-based HTTP client and plugin manifest generator. In affected versions (1.25.1 to < 1.35.0), Kiota propagates the unvalidated x-ai-capabilities.response_semantics.oauth_card_path vendor extension directly into generated API plugin manifests, leading to potential path traversal exploitation by downstream consumers.
TL;DR
Microsoft Kiota versions 1.25.1 to < 1.35.0 fail to validate the oauth_card_path parameter in custom OpenAPI extensions. An attacker can supply a malicious OpenAPI document to generate a compromised plugin manifest containing directory traversal segments, absolute paths, or external URIs, causing downstream execution hosts to access unauthorized files or external servers.
Technical Details
- CWE ID: CWE-22
- Attack Vector: Network
- CVSS v3.1 Score: 3.1
- EPSS Score: Not Registered
- Impact: Low Integrity Impact, Downstream File Disclosure risk
- Exploit Status: Proof-of-Concept
- KEV Status: Not Listed
Affected Systems
- Microsoft Kiota CLI
- Microsoft.OpenApi.Kiota NuGet Package
- Microsoft.OpenApi.Kiota.Builder NuGet Package
-
Microsoft Kiota CLI: >= 1.25.1, < 1.35.0 (Fixed in:
1.35.0) -
Microsoft.OpenApi.Kiota: >= 1.25.1, < 1.35.0 (Fixed in:
1.35.0) -
Microsoft.OpenApi.Kiota.Builder: >= 1.25.1, < 1.35.0 (Fixed in:
1.35.0)
Code Analysis
Commit: fc0f219
Fix: Check if the oauth_card_path in response semantics is a safe file reference before adding it to the generated manifest, outputting a warning log if invalid.
Exploit Details
- GitHub Security Advisory: Information regarding replication of path traversal payloads within standard test vectors.
Mitigation Strategies
- Upgrade all Kiota CLI tools and library references to version 1.35.0 or above.
- Implement static analysis scanning on generated JSON manifests to detect path traversal sequences.
- Configure downstream consumer platforms to enforce strict path isolation boundaries on plugin packages.
Remediation Steps:
- Identify all systems running the Kiota CLI using command: dotnet tool list -g.
- Upgrade the toolchain by running: dotnet tool update -g Microsoft.OpenApi.Kiota.
- Scan existing codebase .csproj files for Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder packages, updating their versions to >= 1.35.0.
- Deploy runtime path-validation updates to engines consuming the generated declarative plugin manifests.
References
- Official Microsoft Kiota Security Advisory
- Fix Commit (fc0f219)
- Kiota Version 1.35.0 Release Details
- NVD CVE-2026-105795 Record
Read the full report for CVE-2026-105795 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)