NUGET · JULY 2026 · EARLY WARNING

Microsoft Kiota Package Reportedly Compromised via Command Injection

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-HQ9Q-27G5-QWPJSeverity: HIGH

An early warning indicates that the Microsoft Kiota package may have been compromised via a command injection vulnerability in the x-ms-kiota-info dependencyInstallCommand, potentially leading to remote code execution.

What happened

Reportedly, a command injection vulnerability has been discovered in the Microsoft Kiota package, specifically within the x-ms-kiota-info dependencyInstallCommand. This vulnerability appears to allow an attacker to execute arbitrary commands, which could lead to remote code execution. The affected components are Microsoft.OpenApi.Kiota (nuget) 1.32.4 and Microsoft.OpenApi.Kiota.Builder (nuget) 1.32.4. As a precaution, it is recommended to avoid running `kiota info` on untrusted OpenAPI descriptions until a patch is released. Users should monitor for any updates from Microsoft regarding this vulnerability. The incident is under investigation, and further details should be consulted from the primary sources.

To assess your exposure, check if your projects are using the affected versions of Microsoft.OpenApi.Kiota or Microsoft.OpenApi.Kiota.Builder. If so, consider the recommended actions to mitigate potential risks. Stay informed by following updates from Microsoft and the GitHub Advisory Database. The severity of this issue is high, and it is crucial to take appropriate measures to protect your systems.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If Microsoft.OpenApi.Kiota is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats