Microsoft Kiota, Path Traversal, CVE-2026-105795 (Low) -DC-Oct2026-2777

Listen to this Post

CVE-2026-105795 is a path traversal vulnerability (CWE-22) in Microsoft Kiota, an OpenAPI-based HTTP client code generator used to produce API plugin manifests for Microsoft 365 Copilot and Teams. The flaw was introduced in Kiota version 1.25.1, which added support for the `x-ai-capabilities.response_semantics.oauth_card_path` manifest field. When Kiota generates an API plugin manifest from an OpenAPI description, it reads this field and copies its value directly into the generated manifest without validating that the reference is a safe, package-relative file path. An attacker who controls or compromises the OpenAPI description can supply parent-directory traversal sequences (e.g., ../../../../etc/passwd), rooted paths, or absolute URIs (e.g., file:///etc/passwd, https://evil.com/card.json`) instead of a legitimate authentication card file within the plugin package. The unsafe reference is then propagated into the generated manifest. The security impact depends on the downstream host's handling of the reference when the plugin is packaged and deployed. A consuming host that resolves the untrusted reference can cross the intended package boundary or use an unintended authentication card, potentially leading to unauthorized credential usage or disclosure of sensitive files outside the plugin package. Importantly, Kiota itself does not read a local file or execute code during manifest generation; the impact materializes only when a downstream consumer resolves the unsafe reference. The vulnerability remained unvalidated through versions 1.34.1 and the separate 1.29.1 security-backport release. Version 1.35.0 fixes the issue by applying the existing safe-file-reference validator tooauth_card_path, dropping unsafe references and emitting a warning. Valid relative card paths remain supported. The CVSS v3.1 base score is 3.1, reflecting the low severity and the requirement for downstream resolution and user interaction. Related advisories GHSA-4jwf-m4wg-8p66 and GHSA-p5rm-jg5c-8c77 cover a similar flaw instatic_template.file`, but their fixes do not enforce validation at the separate `oauth_card_path` emission site.

DailyCVE Form:

Platform: Microsoft Kiota
Version: 1.25.1-1.34.1
Vulnerability: Path traversal
Severity: Low
date: 2026-10-06

Prediction: 2026-10-06

What Undercode Say:

Analytics

Check installed Kiota version
kiota --version
List affected NuGet packages
dotnet list package --vulnerable --include-transitive
Scan OpenAPI descriptions for unsafe oauth_card_path values
grep -r "oauth_card_path" ./openapi-specs/
Example of a malicious OpenAPI description fragment
x-ai-capabilities:
response_semantics:
oauth_card_path: "../../../../etc/passwd"
// Vulnerable code path in Kiota (conceptual)
var oauthCardPath = openApiDocument.Extensions
.GetValue<OpenApiObject>("x-ai-capabilities")?
.GetValue<OpenApiObject>("response_semantics")?
.GetValue<string>("oauth_card_path");
// No validation before writing to manifest
manifest.OAuthCardPath = oauthCardPath;

Exploit: (Educational Purposes!)

1. Attacker crafts an OpenAPI description containing a malicious
x-ai-capabilities.response_semantics.oauth_card_path value.
2. Victim runs kiota generate -d malicious-openapi.yaml -o ./plugin
to generate an API plugin manifest.
3. Kiota copies the unsafe path into the generated manifest without
validation.
4. The plugin is packaged and deployed to a consuming host (e.g.,
Microsoft 365 Copilot).
5. When the host resolves the oauth_card_path reference, it accesses
a file outside the plugin package boundary.
6. Attacker achieves path traversal, potentially reading sensitive
files or substituting an unintended authentication card.

Protection: from this CVE

- Upgrade to Kiota 1.35.0 or later.
- Regenerate all affected plugin manifests after upgrading.
- Generate plugins only from trusted, integrity-protected OpenAPI
descriptions.
- Review generated manifests before packaging or deployment and remove
any oauth_card_path that is not a safe relative reference confined
to the plugin package.
- Do not rely on validation of sibling manifest fields to validate
oauth_card_path.

Impact:

- Cross the intended plugin-package boundary.
- Use an unintended authentication card.
- Potential unauthorized credential usage.
- Potential disclosure of files outside the plugin package.
- No local code execution or file read by Kiota during generation.
- Impact requires downstream host resolution of the unsafe reference.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top