FixVibe

high

Microsoft Kiota Generation-Time SSRF and File Inclusion (CVE-2026-59867)

Microsoft Kiota releases before 1.29.1 and releases from 1.30.0 through 1.32.4 can follow unrestricted external OpenAPI references during client generation. If a developer or CI job processes an attacker-influenced description, the build host may make internal network requests or read local files. FixVibe GitHub repo scans flag affected Kiota versions.

CVE-2026-59867GHSA-rg4h-fpcp-2qm8CWE-22CWE-829CWE-918

Impact

When a developer or CI job runs an affected Microsoft Kiota release on an attacker-controlled or attacker-influenced OpenAPI description, external $ref entries can make the build host fetch remote HTTP(S) resources or read local and out-of-tree files. Referenced content can be inlined into generated client code and later committed or published, creating a path to disclose data that the attacker could not otherwise read. The vendor advisory limits the demonstrated impact to server-side request forgery and remote or local file inclusion; it does not report code execution [S1] [S2].

Root Cause

The affected NuGet packages are Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder. The reviewed advisory lists two disjoint affected ranges for both packages: releases before 1.29.1, and releases from 1.30.0 up to but excluding 1.32.5 [S1] [S2]. Those releases could resolve external OpenAPI references without a default-deny origin or path policy during generation.

Remediation

Upgrade the older release line to 1.29.1, or upgrade the current release line to 1.32.5 or later [S1] [S3] [S4]. Fixed releases deny external references by default unless a trusted origin or path is explicitly allowed. Keep that allow-list narrow, avoid wildcard trust, review external OpenAPI descriptions before generation, and restrict build-worker network and file-system access.

Covered by FixVibe

FixVibe's GitHub repository scans flag affected Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder versions in .NET and NuGet manifests and lockfiles, with the fixed version to upgrade to.