CVE-2026-59859
CVE-2026-59859 updated by NVD
Summary
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $, allowing attacker-controlled ${...}, $var, or {$obj->prop} interpolation constructs to inject arbitrary PHP code into generated model and request-builder classes. This issue is fixed in version 1.29.1 and 1.32.4.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| NuGet | Microsoft.OpenApi.Kiota | — | 1.32.4, 1.29.1 |
| NuGet | Microsoft.OpenApi.Kiota.Builder | — | 1.32.4, 1.29.1 |
Remediation: Upgrade to 1.32.4 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.
Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.
CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.
EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.