NUGET · JULY 2026 · EARLY WARNING

Microsoft Kiota Package Reportedly Compromised via Command Injection

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-HQ9Q-27G5-QWPJSeverity: HIGH

The Microsoft Kiota package is reportedly compromised due to a command injection vulnerability in the x-ms-kiota-info dependencyInstallCommand, potentially allowing remote code execution.

What happened

An early warning has been issued regarding a potential compromise of the Microsoft Kiota package. The vulnerability, tracked as GHSA-HQ9Q-27G5-QWPJ, appears to involve a command injection in the x-ms-kiota-info dependencyInstallCommand. This flaw could allow an attacker to execute arbitrary commands, leading to remote code execution. Affected components include versions of microsoft.kiota.authentication (nuget) prior to 1.32.4.

Professional software engineers using the Microsoft Kiota package should assess their exposure by checking if they are utilizing versions of microsoft.kiota.authentication (nuget) below 1.32.4. It is recommended to upgrade to version 1.32.4 of microsoft.kiota.authentication and avoid using untrusted OpenAPI descriptions with kiota info as a precautionary measure.

The incident is under investigation, and further details should be obtained from the primary sources. Engineers are advised to consult the GitHub Security Advisory [GHSA-hq9q-27g5-qwpj] for the latest information and recommended actions.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If microsoft.kiota.authentication is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats