NONE · 0

CVE-2026-59860

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the descripti...

Vulnerability Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// … comments). When text from an OpenAPI description is written into single-line XML doc comments without stripping newline and Unicode line-terminator characters, an attacker can break out of the /// comment line and inject additional code into generated C# clients. This issue is fixed in version 1.29.1 and 1.32.3.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-59860?

CVE-2026-59860 is a documented vulnerability. Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the descripti...

How severe is CVE-2026-59860?

CVSS scoring is not yet available for CVE-2026-59860. Check NVD for updates.

Is there a patch for CVE-2026-59860?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.