Vulnerabilities
Last updated 2 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators | High Risk 8.8 | 3 hours ago | 3 hours ago |
|
|
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators | High Risk 8.8 | 3 hours ago | 3 hours ago |
|
|
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests | Low Risk 3.1 | 3 hours ago | 3 hours ago |
|
|
Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests | Low Risk 3.1 | 3 hours ago | 3 hours ago |
|
|
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass) | Medium Risk 6.0 | 2 months ago | 1 month ago |
|
|
Kiota: Code Generation Literal Injection | Low Risk 0.0 | 5 months ago | 1 month ago |
|
|
Kiota: Code Generation Literal Injection | Low Risk 0.0 | 5 months ago | 1 month ago |
|
|
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection | High Risk 8.0 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection | High Risk 8.0 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions | Critical 9.5 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions | Critical 9.5 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF | High Risk 8.0 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF | High Risk 8.0 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName | High Risk 8.0 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName | High Risk 8.0 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator | High Risk 7.5 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator | High Risk 7.5 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info` | Critical 9.5 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info` | Critical 9.5 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator | High Risk 8.0 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator | High Risk 8.0 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref | High Risk 7.1 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref | High Risk 7.1 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator | High Risk 7.5 | 2 months ago | 1 month ago |
|
|
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator | High Risk 7.5 | 2 months ago | 1 month ago |
Page 1