{"id":"CVE-2026-59859","aliases":["GHSA-jqwh-526h-c92j"],"url":"https://o3.security/vulnerability/CVE-2026-59859","summary":"Kiota: Code Generation Literal Injection in the PHP Generator","details":"Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $, allowing attacker-controlled ${...}, $var, or {$obj->prop} interpolation constructs to inject arbitrary PHP code into generated model and request-builder classes. This issue is fixed in version 1.29.1 and 1.32.4.","published":"2026-07-16T14:40:27.319Z","modified":"2026-08-19T09:06:19.537089Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"Microsoft.OpenApi.Kiota","fixedVersion":"1.32.4"},{"ecosystem":"NuGet","name":"Microsoft.OpenApi.Kiota.Builder","fixedVersion":"1.32.4"},{"ecosystem":"NuGet","name":"Microsoft.OpenApi.Kiota","fixedVersion":"1.29.1"},{"ecosystem":"NuGet","name":"Microsoft.OpenApi.Kiota.Builder","fixedVersion":"1.29.1"}],"fix":{"url":"https://github.com/microsoft/kiota/commit/5e2a211ac4261988fbdc72c3b268596ea8837b87","label":"microsoft/kiota@5e2a211"},"references":[{"type":"WEB","url":"https://github.com/microsoft/kiota/releases/tag/v1.32.4"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59859.json"},{"type":"ADVISORY","url":"https://github.com/microsoft/kiota/security/advisories/GHSA-jqwh-526h-c92j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59859"},{"type":"FIX","url":"https://github.com/microsoft/kiota/commit/5e2a211ac4261988fbdc72c3b268596ea8837b87"},{"type":"FIX","url":"https://github.com/microsoft/kiota/pull/7863"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T09:06:19.537089Z"}}