Vulnerability Intelligence Report
Kiota: Code Generation Literal Injection in the PHP Generator
CVE-2026-59859
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $, allowing attacker-controlled ${...}, $var, or {$obj->prop} interpolation constructs to inject arbitrary PHP code into generated model and request-builder classes. This issue is fixed in version 1.29.1 and 1.32.4.
No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:1.02%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94: Improper Control of Generation of Code ('Code Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| microsoft | kiota | >= 1.30.0, < 1.31.1 (affected), < 1.29.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.016%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2026-07-07T15:41:53 |
| Published | 2026-07-16T14:40:27 |
| Last Updated | 2026-08-17T15:02:29 |
Community Chatter & Buzz