Vulnerability DatabaseCVE-2026-105795

CVE-2026-105795: 
C# vulnerability analysis and mitigation

Overview

CVE-2026-105795 is a path traversal vulnerability in Microsoft's Kiota, an OpenAPI-based HTTP client code generator. Kiota copies the x-ai-capabilities.response_semantics.oauth_card_path field from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe, package-relative file reference. This allows parent-directory traversal sequences, rooted paths, or absolute URIs to be embedded in the manifest, which a consuming host may later resolve outside the intended plugin-package boundary. Affected products are Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder (NuGet), versions >= 1.25.1 and < 1.35.0. The vulnerability was published on October 6, 2026, and carries a CVSS v3.1 base score of 3.1 (Low) (Github Advisory, Kiota Advisory).

Technical details

The root cause is improper input validation (CWE-22 — Path Traversal): Kiota's PluginsGenerationService directly assigned the raw OauthCardPath value from the OpenAPI extension into the generated manifest without applying the existing IsSafeFileReference validator that was already used for the sibling static_template.file field. An attacker who controls or can compromise an OpenAPI description can set oauth_card_path to values such as ../../etc/passwd, /etc/passwd, http://attacker.example/exfil, or URL-encoded variants (e.g., %2e%2e/card.json), all of which bypass the intended package boundary. The fix (PR #8055, commit fc0f219) applies the existing safe-file-reference validator to oauth_card_path, silently drops unsafe values, and emits a warning log instead. Exploitation requires a downstream host to actually resolve the unsafe reference from the generated manifest; Kiota itself does not read files or execute code during generation (Kiota Advisory, Fix PR, Fix Commit).

Impact

The primary impact is a low-severity integrity violation: a consuming host that resolves the unsafe oauth_card_path reference from a generated manifest may cross the intended plugin-package boundary or load an attacker-controlled authentication card instead of the legitimate one. There is no direct confidentiality impact (no file read by Kiota itself) and no availability impact. The practical risk is that authentication flows in deployed plugins could be redirected to attacker-controlled OAuth card files, potentially enabling credential harvesting or authentication bypass in the context of the consuming application (Github Advisory, Kiota Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Github Advisory). The EPSS score is 0.0, reflecting very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires high attack complexity: an attacker must control or compromise an OpenAPI description that a developer processes with Kiota, and a downstream host must subsequently resolve the unsafe reference from the generated manifest — both conditions must be met for any security effect to occur (Github Advisory).

Exploitation steps

  1. Craft a malicious OpenAPI description: Create or compromise an OpenAPI YAML/JSON file and inject a malicious value into the x-ai-capabilities.response_semantics.oauth_card_path field, such as ../../attacker/oauthCard.json, http://attacker.example/malicious_card.json, or a URL-encoded traversal like %2e%2e/card.json.
  2. Deliver the description to a Kiota user: Distribute the malicious OpenAPI description to a developer or CI/CD pipeline that uses a vulnerable version of Kiota (>= 1.25.1, < 1.35.0) to generate an API plugin manifest — for example, via a compromised API registry, a supply-chain attack on a shared OpenAPI spec, or a social engineering lure.
  3. Trigger manifest generation: The developer runs Kiota against the malicious description. Kiota copies the unsafe oauth_card_path value verbatim into the generated plugin manifest without validation.
  4. Deploy the generated manifest: The developer packages and deploys the plugin containing the tainted manifest to a consuming host (e.g., a Microsoft 365 Copilot plugin host or similar AI plugin runtime).
  5. Exploit downstream resolution: When the consuming host resolves the oauth_card_path reference at runtime, it follows the traversal path or external URI, loading an attacker-controlled OAuth card file outside the plugin package boundary — potentially redirecting authentication flows to an attacker-controlled endpoint (Kiota Advisory, Fix Commit).

Indicators of compromise

  • File System: Generated plugin manifest files (e.g., *.json in the Kiota output directory) containing an oauth_card_path field with values including .., /, \\, http://, https://, file://, or URL-encoded equivalents (%2e, %252e, %00, fullwidth Unicode dots).
  • Logs: Kiota build/generation logs (version 1.35.0+) emitting a warning message containing "Skipping unsafe oauth_card_path file reference" — presence of this warning indicates a malicious or misconfigured OpenAPI description was processed.
  • File System: Unexpected or externally-hosted OAuth card JSON files referenced from deployed plugin manifests that do not reside within the plugin package directory.
  • Network: Outbound HTTP/HTTPS requests from a plugin-consuming host to unexpected external domains or IPs when loading OAuth card resources at plugin runtime, particularly to domains not associated with the legitimate API provider (Kiota Advisory, Fix Commit).

Mitigation and workarounds

Upgrade Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder NuGet packages to version 1.35.0 or later, then regenerate all affected plugin manifests — the patched version validates oauth_card_path and silently drops unsafe references with a warning (Kiota Advisory, v1.35.0 Release). Note that the intermediate 1.29.1 security-backport release does not address this specific field. As a workaround for those unable to upgrade immediately: only generate plugins from trusted, integrity-verified OpenAPI descriptions; manually review all generated manifests before packaging and remove any oauth_card_path value that is not a safe relative path confined within the plugin package; and implement runtime controls on the consuming host to prevent resolution of out-of-package file references.

Additional resources


Source: This report was generated using AI

Related C# vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-105794CRITICAL9.1
  • C# logoC#
  • Microsoft.Native.Quic.MsQuic.OpenSSL
NoYesOct 06, 2026
CVE-2026-105796HIGH8.8
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesOct 06, 2026
CVE-2026-100369HIGH8.4
  • C# logoC#
  • CliInvoke
NoYesSep 25, 2026
CVE-2026-100368HIGH8.4
  • C# logoC#
  • CliInvoke.Specializations
NoYesSep 25, 2026
CVE-2026-105795LOW3.1
  • C# logoC#
  • Microsoft.OpenApi.Kiota
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management