← Back to CVE List
Vulnerability Intelligence Report
Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName

CVE-2026-59866

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when `kiota generate` ran without -c/--class-name, allowing an attacker-controlled or compromised OpenAPI description to write generated source outside the -o output directory and inject arbitrary text into generated class or namespace declarations. This issue is fixed in version 1.29.1 and 1.32.5 by GenerationConfiguration.SanitizeClientClassName and SanitizeClientNamespaceName.

Path Traversal No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
EPSS Probability:1.35%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-22 ↗CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-94 ↗CWE-94: Improper Control of Generation of Code ('Code Injection')

Affected Products & Versions

Vendor Product Affected Versions
microsoft kiota >= 1.30.0, < 1.31.1 (affected), < 1.29.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.355%
Vulnerability Class
Path Traversal

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-07-07T15:41:53
Published2026-07-16T14:46:50
Last Updated2026-08-17T15:03:20

LINK COPIED TO CLIPBOARD