CVE-2026-59866
Critical · CVSS 9.3- CVSS
- 9.3
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-22, CWE-94
Description
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when `kiota generate` ran without -c/--class-name, allowing an attacker-controlled or compromised OpenAPI description to write generated source outside the -o output directory and inject arbitrary text into generated class or namespace declarations. This issue is fixed in version 1.32.5 by GenerationConfiguration.SanitizeClientClassName and SanitizeClientNamespaceName.
Affected packages
| NuGet | Microsoft.OpenApi.Kiota | 0 → 1.32.5 |
| NuGet | Microsoft.OpenApi.Kiota.Builder | 0 → 1.32.5 |
References
Status: profiled · ingested 2026-07-17T06:00:46.000Z