VYPR
High severityNVD Advisory· Published Jul 16, 2026· Updated Jul 29, 2026

Kiota: XML Doc-Comment Newline Breakout Code Injection

CVE-2026-59860

Description

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// … comments). When text from an OpenAPI description is written into single-line XML doc comments without stripping newline and Unicode line-terminator characters, an attacker can break out of the /// comment line and inject additional code into generated C# clients. This issue is fixed in version 1.32.3.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
Microsoft.OpenApi.KiotaNuGet
< 1.32.31.32.3
Microsoft.OpenApi.Kiota.BuilderNuGet
< 1.32.31.32.3

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.