Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6gw6-rv2g-25mg | Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests |
Tue, 06 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI description into a generated API plugin manifest without validating that the value is a safe package-relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a consuming host that resolves the reference, allowing the host to cross the intended plugin-package boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code merely while generating the manifest, and impact requires downstream resolution of the unsafe reference. This issue is fixed in version 1.35.0. | |
| Title | Kiota: Unsafe oauth_card_path references in Kiota-generated API plugin manifests | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T17:17:57.409Z
Reserved: 2026-10-05T20:37:19.364Z
Link: CVE-2026-105795
Updated: 2026-10-06T17:17:48.029Z
Status : Awaiting Analysis
Published: 2026-10-06T15:17:16.437
Modified: 2026-10-06T18:16:47.203
Link: CVE-2026-105795
No data.
OpenCVE Enrichment
Updated: 2026-10-06T18:30:05Z

Github GHSA