
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-105795 is a path traversal vulnerability in Microsoft's Kiota, an OpenAPI-based HTTP client code generator. Kiota copies the x-ai-capabilities.response_semantics.oauth_card_path field from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe, package-relative file reference. This allows parent-directory traversal sequences, rooted paths, or absolute URIs to be embedded in the manifest, which a consuming host may later resolve outside the intended plugin-package boundary. Affected products are Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder (NuGet), versions >= 1.25.1 and < 1.35.0. The vulnerability was published on October 6, 2026, and carries a CVSS v3.1 base score of 3.1 (Low) (Github Advisory, Kiota Advisory).
The root cause is improper input validation (CWE-22 — Path Traversal): Kiota's PluginsGenerationService directly assigned the raw OauthCardPath value from the OpenAPI extension into the generated manifest without applying the existing IsSafeFileReference validator that was already used for the sibling static_template.file field. An attacker who controls or can compromise an OpenAPI description can set oauth_card_path to values such as ../../etc/passwd, /etc/passwd, http://attacker.example/exfil, or URL-encoded variants (e.g., %2e%2e/card.json), all of which bypass the intended package boundary. The fix (PR #8055, commit fc0f219) applies the existing safe-file-reference validator to oauth_card_path, silently drops unsafe values, and emits a warning log instead. Exploitation requires a downstream host to actually resolve the unsafe reference from the generated manifest; Kiota itself does not read files or execute code during generation (Kiota Advisory, Fix PR, Fix Commit).
The primary impact is a low-severity integrity violation: a consuming host that resolves the unsafe oauth_card_path reference from a generated manifest may cross the intended plugin-package boundary or load an attacker-controlled authentication card instead of the legitimate one. There is no direct confidentiality impact (no file read by Kiota itself) and no availability impact. The practical risk is that authentication flows in deployed plugins could be redirected to attacker-controlled OAuth card files, potentially enabling credential harvesting or authentication bypass in the context of the consuming application (Github Advisory, Kiota Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Github Advisory). The EPSS score is 0.0, reflecting very low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires high attack complexity: an attacker must control or compromise an OpenAPI description that a developer processes with Kiota, and a downstream host must subsequently resolve the unsafe reference from the generated manifest — both conditions must be met for any security effect to occur (Github Advisory).
x-ai-capabilities.response_semantics.oauth_card_path field, such as ../../attacker/oauthCard.json, http://attacker.example/malicious_card.json, or a URL-encoded traversal like %2e%2e/card.json.oauth_card_path value verbatim into the generated plugin manifest without validation.oauth_card_path reference at runtime, it follows the traversal path or external URI, loading an attacker-controlled OAuth card file outside the plugin package boundary — potentially redirecting authentication flows to an attacker-controlled endpoint (Kiota Advisory, Fix Commit).*.json in the Kiota output directory) containing an oauth_card_path field with values including .., /, \\, http://, https://, file://, or URL-encoded equivalents (%2e, %252e, %00, fullwidth Unicode dots)."Skipping unsafe oauth_card_path file reference" — presence of this warning indicates a malicious or misconfigured OpenAPI description was processed.Upgrade Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder NuGet packages to version 1.35.0 or later, then regenerate all affected plugin manifests — the patched version validates oauth_card_path and silently drops unsafe references with a warning (Kiota Advisory, v1.35.0 Release). Note that the intermediate 1.29.1 security-backport release does not address this specific field. As a workaround for those unable to upgrade immediately: only generate plugins from trusted, integrity-verified OpenAPI descriptions; manually review all generated manifests before packaging and remove any oauth_card_path value that is not a safe relative path confined within the plugin package; and implement runtime controls on the consuming host to prevent resolution of out-of-package file references.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."