Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-59865

Опубликовано: 16 июл. 2026
Источник: nvd
EPSS Низкий

Описание

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, kiota info read x-ms-kiota-info.languagesInformation..dependencyInstallCommand plus dependency name and version values from an OpenAPI description and presented the spec-supplied command as Kiota's recommended install command, allowing an attacker-controlled or compromised description to cause command injection when the suggested command was run manually or through the Kiota VS Code extension's kiota info --json dependency-install flow. This issue is fixed in version 1.32.5.

EPSS

Процентиль: 87%
0.0319
Низкий

Дефекты

CWE-94

Связанные уязвимости

github
6 дней назад

Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

EPSS

Процентиль: 87%
0.0319
Низкий

Дефекты

CWE-94