CVE-2026-59862

HIGH

Kiota: Code Generation Literal Injection in the Python Generator

Title source: cna
STIX 2.1

Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.values[].description flow through KiotaBuilder.SetEnumOptions into Documentation.DescriptionTemplate and PythonConventionService.RemoveInvalidDescriptionCharacters without newline sanitization, allowing generated inline comments to split and execute attacker-controlled Python code at module scope when generated modules were imported. This issue is fixed in version 1.32.0.

References (2)

Core 2
Core References

Scores

CVSS v3 7.5
EPSS 0.0102
EPSS Percentile 60.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (5)
microsoft/kiota < 1.32.0
nuget/Microsoft.OpenAPI.Kiota 0 - 1.32.0NuGet
nuget/Microsoft.OpenApi.Kiota 0 - 1.32.0NuGet
nuget/Microsoft.OpenAPI.Kiota.Builder 0 - 1.32.0NuGet
nuget/Microsoft.OpenApi.Kiota.Builder 0 - 1.32.0NuGet
Published Jul 16, 2026
Tracked Since Jul 16, 2026