SCA: security update for Microsoft.OpenApi.Kiota, Microsoft.OpenApi.Kiota.Builder (GHSA-6gw6-rv2g-25mg)

low Tenable Cloud Security Plugin ID 473475

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Kiota is an OpenAPI based HTTP Client code generator. From 1.25.1 until 1.35.0, Kiota copies x-ai-
capabilities.response_semantics.oauth_card_path from an attacker-controlled or compromised OpenAPI
description into a generated API plugin manifest without validating that the value is a safe package-
relative file reference. Parent-directory traversal, rooted paths, or absolute URIs can therefore reach a
consuming host that resolves the reference, allowing the host to cross the intended plugin-package
boundary or use an unintended authentication card. Kiota does not itself read a local file or execute code
merely while generating the manifest, and impact requires downstream resolution of the unsafe reference.
This issue is fixed in version 1.35.0. (CVE-2026-105795)

Solution

Update the Microsoft.OpenApi.Kiota library and its related packages to version 1.35.0 or later.

See Also

https://github.com/advisories/GHSA-6gw6-rv2g-25mg

Plugin Details

Severity: Low

ID: 473475

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/7/2026

Updated: 10/7/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.2

Percentile: 50.43

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 1.9

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2026-105795

CVSS v3

Risk Factor: Low

Base Score: 3.1

Temporal Score: 2.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/6/2026

Vulnerability Publication Date: 10/6/2026

Reference Information

CVE: CVE-2026-105795

cwe: CWE-22