CVE-2026-59859

CVE-2026-59859 is a high-severity code injection vulnerability in Microsoft.OpenApi.Kiota (nuget), affecting versions < 1.32.4. It is fixed in 1.32.4.

Does this CVE actually affect you?

Kodem shows which CVEs are reachable and running in your applications, so you fix what's exploitable, not just what's listed.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Runtime intelligence, not another scanner.

Summary

Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator

Who is impacted

Developers using Kiota to generate PHP API clients from external or untrusted OpenAPI specifications

Teams with CI/CD pipelines configured to automatically regenerate client code from remote specs

Applications that deploy generated PHP code to production servers

Vulnerability details

Affected component: StringExtensions.cs

Root cause: The shared SanitizeDoubleQuote() function in Writers/StringExtensions.cs does not escape the $ character. As a result, any schema-derived string emitted as a PHP double-quoted literal preserves $-prefixed interpolation constructs (${...}, $var, {$...}) verbatim, which PHP evaluates at runtime instead of treating as literal text. This is the same class of code-generation literal-injection flaw previously fixed for the Ruby generator (# interpolation), recurring here as a missed variant for PHP's $ interpolation in the sibling sanitizer helper.

Attack vectors

OpenAPI description and default fields in schema properties

Property wire-name keys embedded in deserializer/serializer methods

Any schema-derived string embedded in PHP double-quoted literals

Severity: Critical when generated code reaches production; High for CI/CD environments with access to production secrets; Medium for public third-party specs; Low for developer-controlled specs.

Workarounds

If you cannot upgrade immediately:

  1. Audit and sanitize OpenAPI specifications: Review all OpenAPI specification files for any descriptions, default values, or property names containing the $ character. Remove or replace any suspicious strings before code generation.
  2. Code review of generated files: Implement mandatory code review of all generated PHP files before merging into any branch. Look for double-quoted strings containing ${, $var, or {$ patterns.
  3. Restrict specification sources: Only consume OpenAPI specifications from trusted internal sources. Avoid automatic code generation from external or third-party APIs until this patch is applied.
  4. Isolate generated code from production: Do not deploy generated PHP models to production environments unless the specification source has been verified and reviewed.
  5. Manual escaping (temporary): If regeneration is not possible, manually inspect and edit generated files to escape any $ characters in double-quoted string literals (replace $ with \$).

Remediation

Upgrade Kiota to 1.32.4 or later.

Regenerate/refresh existing generated clients as a precaution:

Refreshing generated clients ensures previously generated vulnerable code is replaced with hardened output.

Impact

The Kiota PHP code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI fields (e.g. description, default values, and property names) directly into PHP double-quoted string literals without properly escaping the $ character. Since PHP evaluates string interpolation expressions like "${expr}", "$var", and "{$obj->prop}" within double-quoted strings at runtime, an attacker who controls an OpenAPI specification file can inject arbitrary PHP code into generated model and request-builder classes.

Untrusted input is evaluated as executable code within the application's runtime environment. Typical impact: arbitrary code execution within the application's privilege context.

Affected versions

Microsoft.OpenApi.Kiota (< 1.32.4) Microsoft.OpenApi.Kiota.Builder (< 1.32.4)

Security releases

Microsoft.OpenApi.Kiota → 1.32.4 (nuget) Microsoft.OpenApi.Kiota.Builder → 1.32.4 (nuget)

Kodem intelligence

Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.

Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.

Already deployed Kodem?

See it in your environmentNew to Kodem? Get a demo →

Remediation advice

#7863

Frequently Asked Questions

  1. What is CVE-2026-59859? CVE-2026-59859 is a high-severity code injection vulnerability in Microsoft.OpenApi.Kiota (nuget), affecting versions < 1.32.4. It is fixed in 1.32.4. Untrusted input is evaluated as executable code within the application's runtime environment.
  2. Which packages are affected by CVE-2026-59859?
    • Microsoft.OpenApi.Kiota (nuget) (versions < 1.32.4)
    • Microsoft.OpenApi.Kiota.Builder (nuget) (versions < 1.32.4)
  3. Is there a fix for CVE-2026-59859? Yes. CVE-2026-59859 is fixed in 1.32.4. Upgrade to this version or later.
  4. Is CVE-2026-59859 exploitable, and should I be worried? Whether CVE-2026-59859 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
  5. What actually determines whether CVE-2026-59859 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
  6. How do I fix CVE-2026-59859?
    • Upgrade Microsoft.OpenApi.Kiota to 1.32.4 or later
    • Upgrade Microsoft.OpenApi.Kiota.Builder to 1.32.4 or later

Other vulnerabilities in Microsoft.OpenApi.Kiota

Stop the waste.
Protect your environment with Kodem.