CVE ID :CVE-2026-59859 Published : July 16, 2026, 3:16 p. m. | 1 hour ago Description :Kiota is an OpenAPI based HTTP Client code generator.
Prior to 1. 32. 4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.
cs without escaping $, allowing attacker-controlled ${...
0 comments
No comments yet. Be the first to start the discussion.