Feed/CVE-2026-59859
CVE-2026-59859HIGHCVSS 0.0

CVE-2026-59859

Published Jul 16, 2026·Updated Aug 17, 2026

NVD Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $, allowing attacker-controlled ${...}, $var, or {$obj->prop} interpolation constructs to inject arbitrary PHP code into generated model and request-builder classes. This issue is fixed in version 1.32.4.

Affected Packages (2)

Microsoft.OpenApi.KiotaNUGET
From 1.30.0
Fixed in 1.32.4
Microsoft.OpenApi.Kiota.BuilderNUGET
From 1.30.0
Fixed in 1.32.4

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free