DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-105795: CVE-2026-105795: Unvalidated Custom Extension Path Traversal in Microsoft Kiota

CVE-2026-105795: Unvalidated Custom Extension Path Traversal in Microsoft Kiota

Vulnerability ID: CVE-2026-105795
CVSS Score: 3.1
Published: 2026-10-06

CVE-2026-105795 (GHSA-6gw6-rv2g-25mg) is a critical path traversal vulnerability in Microsoft Kiota, an OpenAPI-based HTTP client and plugin manifest generator. In affected versions (1.25.1 to < 1.35.0), Kiota propagates the unvalidated x-ai-capabilities.response_semantics.oauth_card_path vendor extension directly into generated API plugin manifests, leading to potential path traversal exploitation by downstream consumers.

TL;DR

Microsoft Kiota versions 1.25.1 to < 1.35.0 fail to validate the oauth_card_path parameter in custom OpenAPI extensions. An attacker can supply a malicious OpenAPI document to generate a compromised plugin manifest containing directory traversal segments, absolute paths, or external URIs, causing downstream execution hosts to access unauthorized files or external servers.


Technical Details

  • CWE ID: CWE-22
  • Attack Vector: Network
  • CVSS v3.1 Score: 3.1
  • EPSS Score: Not Registered
  • Impact: Low Integrity Impact, Downstream File Disclosure risk
  • Exploit Status: Proof-of-Concept
  • KEV Status: Not Listed

Affected Systems

  • Microsoft Kiota CLI
  • Microsoft.OpenApi.Kiota NuGet Package
  • Microsoft.OpenApi.Kiota.Builder NuGet Package
  • Microsoft Kiota CLI: >= 1.25.1, < 1.35.0 (Fixed in: 1.35.0)
  • Microsoft.OpenApi.Kiota: >= 1.25.1, < 1.35.0 (Fixed in: 1.35.0)
  • Microsoft.OpenApi.Kiota.Builder: >= 1.25.1, < 1.35.0 (Fixed in: 1.35.0)

Code Analysis

Commit: fc0f219

Fix: Check if the oauth_card_path in response semantics is a safe file reference before adding it to the generated manifest, outputting a warning log if invalid.

Exploit Details

Mitigation Strategies

  • Upgrade all Kiota CLI tools and library references to version 1.35.0 or above.
  • Implement static analysis scanning on generated JSON manifests to detect path traversal sequences.
  • Configure downstream consumer platforms to enforce strict path isolation boundaries on plugin packages.

Remediation Steps:

  1. Identify all systems running the Kiota CLI using command: dotnet tool list -g.
  2. Upgrade the toolchain by running: dotnet tool update -g Microsoft.OpenApi.Kiota.
  3. Scan existing codebase .csproj files for Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder packages, updating their versions to >= 1.35.0.
  4. Deploy runtime path-validation updates to engines consuming the generated declarative plugin manifests.

References


Read the full report for CVE-2026-105795 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)