Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, kiota info read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install command, allowing an attacker-controlled or compromised description to cause command injection when the suggested command was run manually or through the Kiota VS Code extension's kiota info --json dependency-install flow. This issue is fixed in version 1.29.1 and 1.32.5.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59865.json",
"cwe_ids": [
"CWE-829",
"CWE-94"
],
"cna_assigner": "GitHub_M"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "1.30.0"
},
{
"fixed": "1.31.1"
},
{
"introduced": "0"
},
{
"fixed": "1.29.1"
}
]
}
[
{
"id": "CVE-2026-59865-0255b0db",
"target": {
"file": "it/java/gh/src/test/java/GHAPITest.java"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"66609017551477010826143835577406265593",
"35496344713004664179944048284480170529",
"147500007851372202392601133532187874810",
"240753228186878202917022054237087631710",
"322801780681153563118919792465691120440",
"105331927903652750006918956054969541779",
"92754106178057991798446179728179208061",
"253209821667215414607528288804099395645",
"250008073155348665397373185331785853495",
"64797852886090781921647040874546962214"
]
},
"signature_version": "v1",
"source": "https://github.com/microsoft/kiota/commit/70cd8bcba3ff1815f93187f3eb80ef96fd194d46",
"signature_type": "Line"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59865.json"
"2026-08-19T09:06:20Z"