Impact
When a developer or CI job runs an affected Microsoft Kiota release on an attacker-controlled or attacker-influenced OpenAPI description, external $ref entries can make the build host fetch remote HTTP(S) resources or read local and out-of-tree files. Referenced content can be inlined into generated client code and later committed or published, creating a path to disclose data that the attacker could not otherwise read. The vendor advisory limits the demonstrated impact to server-side request forgery and remote or local file inclusion; it does not report code execution [S1] [S2].
Root Cause
The affected NuGet packages are Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder. The reviewed advisory lists two disjoint affected ranges for both packages: releases before 1.29.1, and releases from 1.30.0 up to but excluding 1.32.5 [S1] [S2]. Those releases could resolve external OpenAPI references without a default-deny origin or path policy during generation.
Remediation
Upgrade the older release line to 1.29.1, or upgrade the current release line to 1.32.5 or later [S1] [S3] [S4]. Fixed releases deny external references by default unless a trusted origin or path is explicitly allowed. Keep that allow-list narrow, avoid wildcard trust, review external OpenAPI descriptions before generation, and restrict build-worker network and file-system access.
Covered by FixVibe
FixVibe's GitHub repository scans flag affected Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder versions in .NET and NuGet manifests and lockfiles, with the fixed version to upgrade to.
