Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota honored a poisoned .kiota/workspace.json workspace configuration without validating per-client or per-plugin outputPath values during kiota client generate and kiota plugin generate, allowing a malicious repository or pull request to use absolute paths, rooted POSIX / paths, UNC \ or // paths, Windows drive X:\ paths, or .. traversal segments to write generated client files outside the workspace root on a developer or CI host. This issue is fixed in version 1.29.1 and 1.32.5.
{
"cwe_ids": [
"CWE-22"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59863.json"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "1.30.0"
},
{
"fixed": "1.31.1"
},
{
"introduced": "0"
},
{
"fixed": "1.29.1"
}
]
}
"2026-08-19T12:09:53Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59863.json"
[
{
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"66609017551477010826143835577406265593",
"35496344713004664179944048284480170529",
"147500007851372202392601133532187874810",
"240753228186878202917022054237087631710",
"322801780681153563118919792465691120440",
"105331927903652750006918956054969541779",
"92754106178057991798446179728179208061",
"253209821667215414607528288804099395645",
"250008073155348665397373185331785853495",
"64797852886090781921647040874546962214"
],
"threshold": 0.9
},
"id": "CVE-2026-59863-0255b0db",
"source": "https://github.com/microsoft/kiota/commit/70cd8bcba3ff1815f93187f3eb80ef96fd194d46",
"target": {
"file": "it/java/gh/src/test/java/GHAPITest.java"
}
}
]