CVE-2026-59864
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, kiota plugin add and kiota plugin generate (with -t APIPlugin) emitted attacker-controlled statictemplate.file values from x-ai-adaptive-card and x-ai-capabilities into generated Microsoft 365 Copilot and Teams plugin manifests without path validation, allowing ../, absolute, rooted, UNC, Windows drive, or URI paths in responsesemantics.static_template.file to cause path traversal or out-of-package file inclusion when the generated plugin was deployed. This issue is fixed in version 1.29.1 and 1.32.5.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/microsoft/kiota/releases/tag/v1.32.5, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59864.json, https://github.com/microsoft/kiota/security/advisories/GHSA-4jwf-m4wg-8p66, https://nvd.nist.gov/vuln/detail/CVE-2026-59864, https://github.com/microsoft/kiota/commit/9a185994a4e549b7bba3cc2beffb9736aa902e79, https://github.com/microsoft/kiota/pull/7892