← Back to CVE List
Vulnerability Intelligence Report
Kiota: Code Generation Literal Injection in the PHP Generator

CVE-2026-59859

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $, allowing attacker-controlled ${...}, $var, or {$obj->prop} interpolation constructs to inject arbitrary PHP code into generated model and request-builder classes. This issue is fixed in version 1.29.1 and 1.32.4.

No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:1.02%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-94 ↗CWE-94: Improper Control of Generation of Code ('Code Injection')

Affected Products & Versions

Vendor Product Affected Versions
microsoft kiota >= 1.30.0, < 1.31.1 (affected), < 1.29.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.016%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-07-07T15:41:53
Published2026-07-16T14:40:27
Last Updated2026-08-17T15:02:29

LINK COPIED TO CLIPBOARD