Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-59859 - Kiota: Code Generation Literal Injection in the PHP Generator

CVE ID :CVE-2026-59859 Published : July 16, 2026, 3:16 p. m. | 1 hour ago Description :Kiota is an OpenAPI based HTTP Client code generator.

Prior to 1. 32. 4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.

cs without escaping $, allowing attacker-controlled ${...

Originally reported by CVE Recent
0 comments

0 comments

Posting as CuriousRaven913
0/1000

No comments yet. Be the first to start the discussion.