New to Telerik Reporting? Start a free 30-day trial
Microsoft.SemanticKernel Vulnerability in Telerik Reporting AI Packages
Environment
| Product | Version |
|---|---|
| Progress® Telerik® Reporting | Prior to 20.0.26.211 |
Description
Microsoft has published an Arbitrary File Write vulnerability in the Semantic Kernel .NET SDK (Microsoft.SemanticKernel.Core).
If your application uses Telerik Reporting AI packages that depend on Telerik.Reporting.AI.RAG, the vulnerable Microsoft.SemanticKernel.Core package can be brought in transitively.
The impacted packages are:
Telerik.Reporting.AI.Microsoft.Extensions.AbstractionsTelerik.Reporting.AI.Microsoft.Extensions.AzureAIInferenceTelerik.Reporting.AI.Microsoft.Extensions.AzureOpenAITelerik.Reporting.AI.Microsoft.Extensions.OllamaTelerik.Reporting.AI.Microsoft.Extensions.OpenAITelerik.Reporting.AI.RAG
Visual Studio may display the warning “This solution contains packages with vulnerabilities” when the vulnerable dependency is present.
Solution
Upgrade the Telerik Reporting AI packages to version 20.0.26.211 or later. This updates the transitive dependency chain and removes the vulnerable Microsoft.SemanticKernel.Core version.