Vulnerability Intelligence Report
Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
CVE-2026-59865
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install command, allowing an attacker-controlled or compromised description to cause command injection when the suggested command was run manually or through the Kiota VS Code extension's kiota info --json dependency-install flow. This issue is fixed in version 1.29.1 and 1.32.5.
No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:3.19%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94: Improper Control of Generation of Code ('Code Injection')
CWE-829 ↗CWE-829: Inclusion of Functionality from Untrusted Control Sphere
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| microsoft | kiota | >= 1.30.0, < 1.31.1 (affected), < 1.29.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
3.190%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2026-07-07T15:41:53 |
| Published | 2026-07-16T14:43:40 |
| Last Updated | 2026-08-17T15:03:03 |
Community Chatter & Buzz