PT-2026-106753 · Kiota · Kiota

CVE-2026-105796

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kiota versions 0.5.0 through 1.34.1
Description Kiota is an OpenAPI based HTTP Client code generator. The Java and PHP documentation-comment sanitizers delete block-comment terminators instead of neutralizing them. This allows overlapping characters to reform a terminator, enabling attacker-controlled OpenAPI text to be placed outside a generated documentation comment. Additionally, the Java sanitizer removes non-ASCII characters after deleting terminators, which can create a new terminator during normalization. Exploitation occurs when a developer or build pipeline generates source from a malicious description and subsequently compiles and loads the Java output or loads the PHP output, resulting in the execution of injected code within the consuming application or build environment context.
Recommendations Upgrade to version 1.35.0 or later and regenerate affected clients. Generate clients only from trusted, integrity-protected OpenAPI descriptions. Review generated Java and PHP source before compiling, loading, or deploying it. Restrict the privileges and secrets available to generation and build environments.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105796
GHSA-RM89-RHWJ-9J92

Affected Products

Kiota