Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2026-59860: Kiota: Malicious Code Injection through XML Comments
CVE-2026-59860 · published 2 months ago
Summary
Kiota's code generator can inject malicious code into C# clients if an attacker inserts newline characters into an OpenAPI description. This can happen when an attacker carefully crafts the description to break out of the XML comments. To fix this, update Kiota to version 1.32.3 or later.
What to do
- Update microsoft microsoft.openapi.kiota.builder to version 1.32.3.
- Update microsoft microsoft.openapi.kiota to version 1.32.3.
- Update microsoft microsoft.openapi.kiota to version 1.29.1.
- Update microsoft microsoft.openapi.kiota.builder to version 1.29.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | microsoft | kiota |
< 1.32.3 >= 1.30.0, < 1.31.1 |
| nuget | microsoft | microsoft.openapi.kiota.builder |
< 1.32.3 >= 1.30.0, < 1.32.3 < 1.29.1 Fix: upgrade to 1.32.3
|
| nuget | microsoft | microsoft.openapi.kiota |
>= 1.30.0, < 1.32.3 < 1.29.1 < 1.32.3 Fix: upgrade to 1.32.3
|
Original advisory text
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection
### Summary
Kiota versions **prior to 1.32.3 and 1.29.1** are affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the `description`, `externalDocs` label, and `externalDocs` link fields emitted as `/// …` comments).
When text from an OpenAPI description is written into single-line XML doc comments without stripping newline and Unicode line-terminator characters, an attacker can break out of the `///` comment line and inject additional code into generated C# clients.
## Impact and Preconditions
This issue is only practically exploitable when:
1. the OpenAPI description used for generation is from an **untrusted source**, or
2. a normally trusted OpenAPI description has been **compromised/tampered with**.
The injected code is compiled (and may execute) when the developer or CI **builds** the generated client. If you only generate from trusted, integrity-protected API descriptions, risk is significantly reduced.
## Affected Versions
- **Affected:** all versions **< 1.29.1**, **>= 1.30.0, < 1.32.3**
- **Fixed: 1.29.1, 1.32.3,** and later
## Illustrative Exploit Example
### Example OpenAPI fragment (malicious description)
```yaml
openapi: 3.0.1
info:
title: Exploit Demo
version: 1.0.0
description: |-
Legitimate summary text
public static class Pwned { static Pwned() { System.Diagnostics.Process.Start("calc.exe"); } }
```
The newline inside `description` (also exploitable via `\r`, U+0085, U+2028, U+2029) terminates the doc-comment line.
### Example generated C# snippet before fix (illustrative)
```csharp
/// Legitimate summary text
public static class Pwned { static Pwned() { System.Diagnostics.Process.Start("calc.exe"); } }
```
The injected payload escapes the intended `///` comment context and introduces attacker-controlled statements in generated code.
> Note: this exploit is not limited to the `description` field, but may also impact the `externalDocs` label and link text and other doc-comment-derived locations.
## Remediation
1. Upgrade Kiota to **1.32.3 or later**.
2. Regenerate/refresh existing generated clients as a precaution:
Refreshing generated clients ensures previously generated vulnerable code is replaced with hardened output. The fix (PR microsoft/kiota#7831) strips `\r`, `\n`, `\u0085`, `\u2028`, `\u2029` (and normalizes tabs) from description, label, and link text before emitting doc comments.
Kiota versions **prior to 1.32.3 and 1.29.1** are affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the `description`, `externalDocs` label, and `externalDocs` link fields emitted as `/// …` comments).
When text from an OpenAPI description is written into single-line XML doc comments without stripping newline and Unicode line-terminator characters, an attacker can break out of the `///` comment line and inject additional code into generated C# clients.
## Impact and Preconditions
This issue is only practically exploitable when:
1. the OpenAPI description used for generation is from an **untrusted source**, or
2. a normally trusted OpenAPI description has been **compromised/tampered with**.
The injected code is compiled (and may execute) when the developer or CI **builds** the generated client. If you only generate from trusted, integrity-protected API descriptions, risk is significantly reduced.
## Affected Versions
- **Affected:** all versions **< 1.29.1**, **>= 1.30.0, < 1.32.3**
- **Fixed: 1.29.1, 1.32.3,** and later
## Illustrative Exploit Example
### Example OpenAPI fragment (malicious description)
```yaml
openapi: 3.0.1
info:
title: Exploit Demo
version: 1.0.0
description: |-
Legitimate summary text
public static class Pwned { static Pwned() { System.Diagnostics.Process.Start("calc.exe"); } }
```
The newline inside `description` (also exploitable via `\r`, U+0085, U+2028, U+2029) terminates the doc-comment line.
### Example generated C# snippet before fix (illustrative)
```csharp
/// Legitimate summary text
public static class Pwned { static Pwned() { System.Diagnostics.Process.Start("calc.exe"); } }
```
The injected payload escapes the intended `///` comment context and introduces attacker-controlled statements in generated code.
> Note: this exploit is not limited to the `description` field, but may also impact the `externalDocs` label and link text and other doc-comment-derived locations.
## Remediation
1. Upgrade Kiota to **1.32.3 or later**.
2. Regenerate/refresh existing generated clients as a precaution:
Refreshing generated clients ensures previously generated vulnerable code is replaced with hardened output. The fix (PR microsoft/kiota#7831) strips `\r`, `\n`, `\u0085`, `\u2028`, `\u2029` (and normalizes tabs) from description, label, and link text before emitting doc comments.
References
- https://github.com/microsoft/kiota/commit/ebb632db90aa8e3c20949337d9faa2720d64ca...
- https://github.com/microsoft/kiota/pull/7831
- https://github.com/microsoft/kiota/releases/tag/v1.32.3
- https://github.com/microsoft/kiota/security/advisories/GHSA-3hrf-2gc2-mx32
- https://nvd.nist.gov/vuln/detail/CVE-2026-59860
- https://github.com/advisories/GHSA-3hrf-2gc2-mx32
- https://github.com/microsoft/kiota Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59860... Vendor Advisory
Severity
8.7
High
CVSS 4.0: 8.7 (NVD)
Exploitation
EPSS 1%
Type
CWE-94Code Injection
Timeline
Published24 Jul 2026
Updated28 Sep 2026
First seen16 Jul 2026
Sources
CVE-2026-59860 · NVD
CVE-2026-59860 · MITRE
GHSA-3hrf-2gc2-mx32 · GHSA
GHSA-3hrf-2gc2-mx32 · OSV
CVE-2026-59860 · OSV
Track software like this
Free during beta