Security Advisory

CVE-2026-73851

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-17 15:11:39
Last updated 2026-08-17 15:26:40
Assigner GitHub_M
CVSS score 6.1
State PUBLISHED

Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that resolves outside the manifest package (e.g. ../../../../etc/passwd, an absolute path, or a file:// / http(s):// URI). When the generated manifest is deployed and consumed by an AI host, this can lead to inclusion or disclosure of files outside the intended package boundary. This vulnerability is fixed in 1.29.1 and 1.34.0.