Skip to content
CVE / MITRECVE RecentΒ·Β·1 min read

CVE-2026-59862 - Kiota: Code Generation Literal Injection in the Python Generator

CVE ID :CVE-2026-59862 Published : July 16, 2026, 3:16 p. m. | 1 hour ago Description :Kiota is an OpenAPI based HTTP Client code generator.

Prior to 1. 32. 0, Kiota's Python generator let attacker-controlled enum value descriptions from x-ms-enum.

values[]. description flow through KiotaBuilder. SetEnumOptions into Documentation.

DescriptionTemplate and PythonConventionService.

Originally reported by CVE Recent
0 comments

0 comments

Posting as WittyBadger959
0/1000

No comments yet. Be the first to start the discussion.