CVE-2026-59867
HIGHKiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
Title source: cnaDescription
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota resolved OpenAPI $ref values by fetching remote http(s) URLs and reading local absolute or out-of-tree file paths, allowing `kiota generate` on an attacker-controlled or attacker-influenced description to perform build-time SSRF, remote file inclusion, and local file inclusion by inlining external schemas such as REMOTE_KIOTA_PROP or Leaked into generated clients. This issue is fixed in version 1.32.5 by AllowedExternalOriginsStreamLoader and the --allowed-external-origins option.
References (4)
Core 4
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/microsoft/kiota/security/advisories/GHSA-rg4h-fpcp-2qm8
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/kiota/pull/7888
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/kiota/commit/cccd798027f0a20db796b3df6c64f9897a39d7b1
X_Refsource_Misc x_refsource_misc
https://github.com/microsoft/kiota/releases/tag/v1.32.5
Scores
CVSS v3
7.1
EPSS
0.0192
EPSS Percentile
77.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
CWE-829
CWE-918
Status
published
Products (3)
microsoft/kiota
< 1.32.5
nuget/Microsoft.OpenApi.Kiota
0 - 1.32.5NuGet
nuget/Microsoft.OpenApi.Kiota.Builder
0 - 1.32.5NuGet
Published
Jul 16, 2026
Tracked Since
Jul 16, 2026