Microsoft kiota-typescript是美国Microsoft公司的根据产品名称和生成代码的上下文,这是一个用于生成TypeScript客户端代码的库。 Microsoft kiota-typescript 1.0.0-preview.97版本至1.0.0-preview.101版本存在输入验证错误漏洞,该漏洞可导致Cookie泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| microsoft | kiota-typescript | >= 1.0.0-preview.97, < 1.0.0-preview.102 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| microsoft | kiota-typescript | >= 1.0.0-preview.97, < 1.0.0-preview.102 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45480 | 10.0 CRITICAL | Azure Active Directory Elevation of Privilege Vulnerability |
| CVE-2026-48584 | 9.9 CRITICAL | Microsoft Azure Synapse Elevation of Privilege Vulnerability |
| CVE-2026-48582 | 9.6 CRITICAL | Microsoft Exchange Online Elevation of Privilege Vulnerability |
| CVE-2026-32208 | 8.8 HIGH | Microsoft Entra ID Spoofing Vulnerability |
| CVE-2026-47645 | 8.8 HIGH | Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability |
| CVE-2026-42895 | 6.5 MEDIUM | Microsoft Copilot Tampering Vulnerability |
| CVE-2026-50519 | 6.5 MEDIUM | Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability |
No comments yet