Kiota Python Code Generator Vulnerable to Arbitrary Code Execution
The Kiota Python code generator is reportedly vulnerable to a code generation literal injection issue that can lead to arbitrary code execution. Malicious OpenAPI specifications can cause arbitrary Python code to be emitted into generated model files, executing when the affected module is imported.
What happened
An early warning has been issued regarding a vulnerability in the Kiota Python code generator. The issue, tracked as GHSA-7F3J-J7JJ-R3VR, involves a code generation literal injection that can lead to arbitrary code execution. According to the advisory, malicious OpenAPI specifications can cause arbitrary Python code to be emitted into generated model files. This code is then executed when the affected module is imported. The vulnerability is under investigation, and it is recommended to avoid generating Python SDKs from untrusted OpenAPI specifications until a patch is available. For more details, consult the primary sources listed in the threat data.
How 0Day mitigates this
kiota is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.