CVE-2026-59864
A flaw in Kiota, an OpenAPI HTTP client generator, lets attackers insert malicious file paths into generated Microsoft 365 Copilot and Teams plugin manifests. The vulnerability can cause path traversal or unintended file inclusion when the plugin is deployed. It was fixed in Kiota 1.32.5.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Kiota versions earlier than 1.32.5, used to generate Microsoft 365 Copilot and Teams plugins.
Real-world impact
An attacker could craft a plugin manifest that points to arbitrary files on the host system, potentially reading sensitive data or executing code when the plugin is installed.
Why this severity
The CVSS score of 9.3 reflects the high potential for attackers to read or modify critical files (confidentiality, integrity, availability) with no authentication or user interaction required.
What to do about it
- 01Upgrade Kiota to version 1.32.5 or later.
NVD-referenced vendor advisory
Timeline
- Jul 16, 2026 · 17d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 19, 2026 · 15d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.