Microsoft Kiota Package Compromised via Command Injection Vulnerability
An early warning indicates that the Microsoft Kiota package may have been compromised via a command injection vulnerability in the x-ms-kiota-info dependencyInstallCommand. This could allow an attacker to execute arbitrary commands, leading to potential remote code execution.
What happened
Reportedly, the Microsoft Kiota package was compromised through a command injection vulnerability present in the x-ms-kiota-info dependencyInstallCommand. This vulnerability could enable an attacker to execute arbitrary commands, potentially leading to remote code execution. The vulnerability appears to be triggered when running the `kiota info` command on untrusted OpenAPI descriptions. It is recommended to avoid using `kiota info` on untrusted OpenAPI descriptions until a patch is released. The affected components include Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder, with various versions impacted. For detailed version information, please consult the primary sources. Microsoft is under investigation for this vulnerability, and further updates are expected.
How 0Day mitigates this
Microsoft.OpenApi.Kiota is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.