VYPR
Critical severityNVD Advisory· Published Jul 16, 2026· Updated Jul 29, 2026

Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

CVE-2026-59865

Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, kiota info read x-ms-kiota-info.languagesInformation..dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install command, allowing an attacker-controlled or compromised description to cause command injection when the suggested command was run manually or through the Kiota VS Code extension's kiota info --json dependency-install flow. This issue is fixed in version 1.32.5.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.OpenApi.KiotaNuGet
< 1.32.51.32.5
Microsoft.OpenApi.Kiota.BuilderNuGet
< 1.32.51.32.5

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.