Code Generation Injection Vulnerability in Kiota by Microsoft
CVE-2026-59860

8.7HIGH

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
16 July 2026

What is CVE-2026-59860?

Kiota, Microsoft's OpenAPI based HTTP Client code generator, is susceptible to a code-generation injection vulnerability prior to version 1.32.3. This issue arises in the C# XML documentation-comment sink, where the system fails to properly handle newline and Unicode line-terminator characters when emitting comments. As a consequence, an attacker could manipulate the comments to inject unintended code into the generated C# clients. This vulnerability has been addressed and resolved in Kiota version 1.32.3.

Affected Version(s)

kiota < 1.32.3

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.