Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-59863 - Kiota: Workspace-config poisoning: out-of-repo file write + generation-time SSRF

CVE ID :CVE-2026-59863 Published : July 16, 2026, 3:16 p. m. | 1 hour ago Description :Kiota is an OpenAPI based HTTP Client code generator.

Prior to 1. 32. 5, Kiota honored a poisoned .

kiota/workspace. json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a malicious repository or pull request to use absolute paths, rooted POSIX / paths, UNC \\ or // paths, Windows drive X:\ paths, or ..

Originally reported by CVE Recent
0 comments

0 comments

Posting as BoldMantis795
0/1000

No comments yet. Be the first to start the discussion.