CVE ID :CVE-2026-59863 Published : July 16, 2026, 3:16 p. m. | 1 hour ago Description :Kiota is an OpenAPI based HTTP Client code generator.
Prior to 1. 32. 5, Kiota honored a poisoned .
kiota/workspace. json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a malicious repository or pull request to use absolute paths, rooted POSIX / paths, UNC \\ or // paths, Windows drive X:\ paths, or ..
0 comments
No comments yet. Be the first to start the discussion.