Skip to content

Kiota: Code injection through doc-comment delimiter reformation in Kiota Java and PHP generators

High severity GitHub Reviewed Published Oct 1, 2026 in microsoft/kiota • Updated Oct 6, 2026

Package

nuget Microsoft.OpenApi.Kiota (NuGet)

Affected versions

>= 0.5.0, < 1.35.0

Patched versions

1.35.0
nuget Microsoft.OpenApi.Kiota.Builder (NuGet)
>= 0.5.0, < 1.35.0
1.35.0

Description

Impact

An attacker who controls or tampers with an OpenAPI description can cause Kiota to emit attacker-controlled Java or PHP source outside a generated documentation comment. The affected sanitizers remove comment terminators rather than neutralizing them, allowing a terminator to reform from overlapping characters or from subsequent normalization. The Java sanitizer also removes non-ASCII characters after removing terminators, which can create a new terminator.

Exploitation requires a developer or build pipeline to generate a client from the malicious description and subsequently compile and load the Java output, or load the PHP output. Code executes in the consuming application's or build environment's security context, not merely because Kiota reads the description.

Affected versions

The affected NuGet packages are Microsoft.OpenApi.Kiota and Microsoft.OpenApi.Kiota.Builder. The Java normalization-order defect was introduced in version 0.5.0 and remains present through version 1.34.1, including the separate 1.29.1 security-backport release. The PHP delimiter-reformation variant is also present in version 1.34.1 and 1.29.1. Version 1.35.0 fixes both variants.

The package version range below reflects the Java defect; it does not assert that PHP generation existed in every version in that range.

Patches

Upgrade to Kiota 1.35.0 or later and regenerate affected clients. The fix neutralizes block-comment delimiters instead of deleting them, and performs Java delimiter neutralization after non-ASCII normalization.

Workarounds

Until upgrading, generate clients only from trusted, integrity-protected OpenAPI descriptions. Review generated Java and PHP source before compiling, loading, or deploying it. Restrict the privileges and secrets available to generation and build environments.

Related advisories

This is distinct from PHP double-quoted string interpolation (GHSA-jqwh-526h-c92j) and C# XML documentation newline breakout (GHSA-3hrf-2gc2-mx32). Those fixes do not address Java/PHP block-comment delimiter reformation.

References

@gavinbarron gavinbarron published to microsoft/kiota Oct 1, 2026
Published by the National Vulnerability Database Oct 6, 2026
Published to the GitHub Advisory Database Oct 6, 2026
Reviewed Oct 6, 2026
Last updated Oct 6, 2026

Severity

High

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS score

Weaknesses

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. Learn more on MITRE.

CVE ID

CVE-2026-105796

GHSA ID

GHSA-rm89-rhwj-9j92

Source code

Credits

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.