Code Generation Injection Vulnerability in Kiota by Microsoft
CVE-2026-59860
8.7HIGH
What is CVE-2026-59860?
Kiota, Microsoft's OpenAPI based HTTP Client code generator, is susceptible to a code-generation injection vulnerability prior to version 1.32.3. This issue arises in the C# XML documentation-comment sink, where the system fails to properly handle newline and Unicode line-terminator characters when emitting comments. As a consequence, an attacker could manipulate the comments to inject unintended code into the generated C# clients. This vulnerability has been addressed and resolved in Kiota version 1.32.3.
Affected Version(s)
kiota < 1.32.3