← Back to CVE List
Vulnerability Intelligence Report
Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

CVE-2026-59865

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install command, allowing an attacker-controlled or compromised description to cause command injection when the suggested command was run manually or through the Kiota VS Code extension's kiota info --json dependency-install flow. This issue is fixed in version 1.29.1 and 1.32.5.

No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:3.19%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-94 ↗CWE-94: Improper Control of Generation of Code ('Code Injection')
CWE-829 ↗CWE-829: Inclusion of Functionality from Untrusted Control Sphere

Affected Products & Versions

Vendor Product Affected Versions
microsoft kiota >= 1.30.0, < 1.31.1 (affected), < 1.29.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
3.190%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-07-07T15:41:53
Published2026-07-16T14:43:40
Last Updated2026-08-17T15:03:03

LINK COPIED TO CLIPBOARD