NONE · 0

CVE-2026-73851

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that re...

Vulnerability Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI). When the generated manifest is deployed and consumed by an AI host, this can lead to inclusion or disclosure of files outside the intended package boundary. This vulnerability is fixed in 1.29.1 and 1.34.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-73851?

CVE-2026-73851 is a documented vulnerability. Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that re...

How severe is CVE-2026-73851?

CVSS scoring is not yet available for CVE-2026-73851. Check NVD for updates.

Is there a patch for CVE-2026-73851?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.