CVE-2026-59861

HIGH

Kiota: Code Generation Literal Injection in Kiota Ruby Generator

Title source: cna
STIX 2.1

Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby double-quoted literals without escaping #, allowing attacker-controlled #{expr}, #$var, or #@var interpolation markers to inject arbitrary Ruby code into generated model classes. This issue is fixed in version 1.32.0.

Scores

CVSS v3 7.5
EPSS 0.0147
EPSS Percentile 71.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (5)
microsoft/kiota < 1.32.0
nuget/Microsoft.OpenAPI.Kiota 0 - 1.32.0NuGet
nuget/Microsoft.OpenApi.Kiota 0 - 1.32.0NuGet
nuget/Microsoft.OpenAPI.Kiota.Builder 0 - 1.32.0NuGet
nuget/Microsoft.OpenApi.Kiota.Builder 0 - 1.32.0NuGet
Published Jul 16, 2026
Tracked Since Jul 16, 2026