Microsoft Kiota Nuget Package Path/URL Injection Vulnerability
An early warning has been issued regarding a potential path/URL injection vulnerability in the Microsoft Kiota nuget package, affecting versions prior to 1.32.4. This vulnerability could allow for path traversal and file inclusion attacks.
What happened
The vulnerability reportedly allows path/URL injection into generated Copilot plugin manifests via x-AI-* extensions, leading to potential path traversal and file inclusion vulnerabilities. This occurs when attacker-controlled input is embedded into the manifest's static_template.file without validation.
The recommended action is to upgrade to kiota version 1.32.4 or higher, and review and sanitize any AI-plugin extensions used in your projects. The affected component is kiota (nuget) version prior to 1.32.4.
For more detailed information, consult the primary sources: [GHSA-4jwf-m4wg-8p66](https://github.com/advisories/GHSA-4jwf-m4wg-8p66) and [GHSA-4rj6-vrwv-wr8m](https://github.com/microsoft/kiota/security/advisories/GHSA-4rj6-vrwv-wr8m).
How 0Day mitigates this
kiota is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.