Vulnerability Intelligence Report
Kiota: XML Doc-Comment Newline Breakout Code Injection
CVE-2026-59860
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// … comments). When text from an OpenAPI description is written into single-line XML doc comments without stripping newline and Unicode line-terminator characters, an attacker can break out of the /// comment line and inject additional code into generated C# clients. This issue is fixed in version 1.29.1 and 1.32.3.
No Active Exploit Signals
CVSS Base Score
8.7
HIGH
EPSS Probability:1.02%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94: Improper Control of Generation of Code ('Code Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| microsoft | kiota | >= 1.30.0, < 1.31.1 (affected), < 1.29.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
1.016%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2026-07-07T15:41:53 |
| Published | 2026-07-16T14:34:24 |
| Last Updated | 2026-08-17T15:01:37 |
Community Chatter & Buzz