GHSA-6gw6-rv2g-25mg: Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests
- Identifiers
- CVE-2026-105795GHSA-6gw6-rv2g-25mg
- Published
- Record updated
Summary
Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder, from version 1.25.1 through 1.34.1 (including the 1.29.1 security-backport release), copy x-ai-capabilities.response_semantics.oauth_card_path into generated API plugin manifests without checking that it is a safe package-relative file reference. An attacker who controls the OpenAPI description can supply parent-directory traversal, rooted paths, or absolute URIs, and a consuming host that resolves the reference may cross the package boundary or use an unintended authentication card. Kiota itself does not read files or execute code during generation.
Mitigation
Upgrade to Kiota 1.35.0 or later and regenerate affected plugin manifests. Kiota 1.35.0 applies the existing safe-file-reference validator to oauth_card_path, drops unsafe references, and emits a warning; valid relative card paths remain supported. Workaround: generate plugins only from trusted, integrity-protected OpenAPI descriptions, and before packaging or deployment review generated manifests and remove any oauth_card_path that is not a safe relative reference confined to the plugin package.
Related items
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSame vendor · BleepingComputer
- InfoAnthropic bans users from being 'cruel' to its AI systemsSame vendor · BBC Technology
- InfoThe Download: AI’s refusal problem and weight-loss drug side effectsSame vendor · MIT Technology Review
- HighGHSA-h4xc-3qfq-jf93: Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpointSame vendor · GitHub Advisory Database
- InfoMicrosoft Teams to get support for third-party deepfake detection toolsSame vendor · BleepingComputer