Vulnerability GHSA-p5rm-jg5c-8c77

Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 months ago
July 24, 2026 at 04:14 PM UTC
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 and 1.33.0
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 and 1.33.0

Summary

Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)

Details

Impact

Kiota generates AI plugin manifests from an OpenAPI description. When the description contains an x-ai-capabilities response semantics static_template (or the adaptive-card extension x-ai-adaptive-card), the file reference is written into the generated manifest's response_semantics.static_template.file and is later resolved by the AI host relative to the plugin package.

An attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI). When the generated manifest is deployed and consumed by an AI host, this can lead to inclusion or disclosure of files outside the intended package boundary (CWE-22 Path Traversal, CWE-829 Inclusion of Functionality from an Untrusted Control Sphere).

A mitigation shipped in v1.32.5 (ExtensionResponseSemanticsStaticTemplate.IsSafeFileReference) rejected literal traversal, rooted paths, drive-qualified paths, and absolute URIs. However, that check inspected the raw reference string, so percent-encoded payloads bypassed every check and were still emitted verbatim. Examples that were incorrectly accepted as safe:

Input Decodes to
%2e%2e/card.json ../card.json
..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd ../../../../../../etc/passwd
file%3A%2F%2F%2Fetc%2Fpasswd file:///etc/passwd
%2e%2e%2f%2e%2e%2f%2e%2e%2fetc%2fpasswd ../../../etc/passwd

Multi-level (double) encoding such as %252e%252e%252fcard.json was also affected. A follow-up review found additional residual bypasses of the same validator: an embedded NUL byte (%00) that truncated the path and defeated the parent-directory segment check, encoding nested deeper than the decode budget (which failed open), and Unicode full-width homoglyphs (e.g. %EF%BC%8E%EF%BC%8E → ..).

Patches

Users should upgrade to the first released Microsoft.OpenApi.Kiota version that includes these fixes (the release following 1.33.0).

Workarounds

  • Only generate clients/plugins from trusted OpenAPI descriptions.
  • Review generated plugin manifests before deployment and reject any response_semantics.static_template.file value that is not a simple relative path within the adaptiveCards/ package folder (no .., no rooted/absolute paths, no URIs, no percent-encoded separators).

References

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
  • CWE-829: Inclusion of Functionality from an Untrusted Control Sphere
  • Affected code: src/Kiota.Builder/OpenApiExtensions/OpenApiAiCapabilitiesExtension.cs (IsSafeFileReference) and enforcement in src/Kiota.Builder/Plugins/PluginsGenerationService.cs.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Low Risk
3 hours ago
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests
1.25.1 - 1.31.1 and 1.33.0 - 1.34.1 GHSA-6gw6-rv2g-25mg
1.25.1 - 1.31.1 and 1.33.0 - 1.34.1 GHSA-6gw6-rv2g-25mg
High Risk
3 hours ago
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators
0.5.1 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 and 1.33.0 - 1.34.1 GHSA-rm89-rhwj-9j92
0.5.1 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 and 1.33.0 - 1.34.1 GHSA-rm89-rhwj-9j92
High Risk
2 months ago
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 GHSA-4vv7-jj25-4gh6
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 GHSA-4vv7-jj25-4gh6
Critical
2 months ago
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 GHSA-hq9q-27g5-qwpj
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 GHSA-hq9q-27g5-qwpj
High Risk
2 months ago
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 GHSA-4rj6-vrwv-wr8m
0.2.0 - 0.6.0 and 0.7.1 and 0.8.3 - 1.0.1 and 1.2.0 - 1.5.1 and 1.6.1 - 1.7.0 and 1.9.0 - 1.21.0 and 1.23.0 and 1.25.1 - 1.31.1 GHSA-4rj6-vrwv-wr8m
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
2 months ago
July 24, 2026 at 04:14 PM UTC
Fixed (1.34.0)
2 months ago
July 08, 2026 at 09:05 PM UTC
Fixed (1.29.1)
1 month ago
August 14, 2026 at 03:16 PM UTC
Last Modified
1 month ago
August 17, 2026 at 03:25 PM UTC