Feed/CVE-2026-59860
CVE-2026-59860HIGHCVSS 0.0

CVE-2026-59860

Published Jul 16, 2026·Updated Aug 17, 2026

NVD Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// … comments). When text from an OpenAPI description is written into single-line XML doc comments without stripping newline and Unicode line-terminator characters, an attacker can break out of the /// comment line and inject additional code into generated C# clients. This issue is fixed in version 1.32.3.

Affected Packages (2)

Microsoft.OpenApi.Kiota.BuilderNUGET
From 1.30.0
Fixed in 1.32.3
Microsoft.OpenApi.KiotaNUGET
From 1.30.0
Fixed in 1.32.3

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free