Disclosure summary
Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outside a generated documentation comment. The Java sanitizer also removes non-ASCII characters after deleting terminators, which can create a new terminator during normalization. Exploitation requires a developer or build pipeline to generate source from the malicious description and then compile and load the Java output or load the PHP output, after which injected code executes in the consuming application or build environment context. The version range is based on the Java defect and does not assert that PHP generation existed in every affected release. This issue is fixed in version 1.35.0.
Source-reported weakness categories
CWE-94
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-rm89-rhwj-9j92
Open original source · Updated Oct 06, 2026
Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| nuget | Microsoft.OpenApi.Kiota | >= 0.5.0, < 1.35.0 | 1.35.0 |
| nuget | Microsoft.OpenApi.Kiota.Builder | >= 0.5.0, < 1.35.0 | 1.35.0 |
NIST National Vulnerability Database · NVD-CVE-2026-105796
Open original source · Updated Oct 06, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-10-06T11:17:16-04:00
MODIFIED 2026-10-06T11:17:16-04:00
INGESTED 2026-10-06T11:45:53-04:00