CVE-2026-59859: Microsoft Kiota
High severity, CVSS 8.7. EPSS: 1.4% chance of exploitation in the next 30 days.
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $, allowing attacker-controlled ${...}, $var, or {$obj->prop} interpolation constructs to inject arbitrary PHP code into generated model and request-builder classes. This issue is fixed in version 1.29.1 and 1.32.4.
Affected products
- Microsoft Kiota: from 1.30.0, before 1.31.1 (fixed in 1.31.1); before 1.29.1 (fixed in 1.29.1)
Published 2026-07-16. Last modified 2026-08-17.