High severityNVD Advisory· Published Jul 16, 2026· Updated Jul 29, 2026
Kiota: XML Doc-Comment Newline Breakout Code Injection
CVE-2026-59860
Description
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.3, Kiota is affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the description, externalDocs label, and externalDocs link fields emitted as /// … comments). When text from an OpenAPI description is written into single-line XML doc comments without stripping newline and Unicode line-terminator characters, an attacker can break out of the /// comment line and inject additional code into generated C# clients. This issue is fixed in version 1.32.3.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Microsoft.OpenApi.KiotaNuGet | < 1.32.3 | 1.32.3 |
Microsoft.OpenApi.Kiota.BuilderNuGet | < 1.32.3 | 1.32.3 |
Affected products
1- Range: <1.32.3
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-3hrf-2gc2-mx32ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59860ghsaADVISORY
- github.com/microsoft/kiota/commit/ebb632db90aa8e3c20949337d9faa2720d64ca44ghsax_refsource_MISCWEB
- github.com/microsoft/kiota/pull/7831ghsax_refsource_MISCWEB
- github.com/microsoft/kiota/releases/tag/v1.32.3ghsax_refsource_MISCWEB
- github.com/microsoft/kiota/security/advisories/GHSA-3hrf-2gc2-mx32ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.