PT-2026-106753 · Kiota · Kiota
CVE-2026-105796
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kiota versions 0.5.0 through 1.34.1
Description
Kiota is an OpenAPI based HTTP Client code generator. The Java and PHP documentation-comment sanitizers delete block-comment terminators instead of neutralizing them. This allows overlapping characters to reform a terminator, enabling attacker-controlled OpenAPI text to be placed outside a generated documentation comment. Additionally, the Java sanitizer removes non-ASCII characters after deleting terminators, which can create a new terminator during normalization. Exploitation occurs when a developer or build pipeline generates source from a malicious description and subsequently compiles and loads the Java output or loads the PHP output, resulting in the execution of injected code within the consuming application or build environment context.
Recommendations
Upgrade to version 1.35.0 or later and regenerate affected clients.
Generate clients only from trusted, integrity-protected OpenAPI descriptions.
Review generated Java and PHP source before compiling, loading, or deploying it.
Restrict the privileges and secrets available to generation and build environments.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kiota