{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3amicrosoftkiota/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:microsoft:kiota:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-105796"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Microsoft.OpenApi.Kiota (\u003c 1.35.0)","Microsoft.OpenApi.Kiota.Builder (\u003c 1.35.0)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","code-injection","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Microsoft"],"content_html":"\u003cp\u003eMicrosoft Kiota versions prior to 1.35.0 contain a vulnerability (CVE-2026-105796) in the Java and PHP generators that allows for code injection during the client generation process. The sanitization logic within the generators incorrectly attempts to remove block-comment delimiters (such as '*/') rather than neutralizing them. This approach allows an attacker who controls an OpenAPI description to craft input that causes these delimiters to reform after the sanitization step, either through overlapping characters or normalization processes. In the Java generator, the removal of non-ASCII characters after the initial sanitization can also trigger the creation of new comment terminators.\u003c/p\u003e\n\u003cp\u003eWhen a developer or an automated build pipeline uses Kiota to generate a client from a malicious OpenAPI definition, the resulting Java or PHP source code contains injected payloads outside of the intended documentation comments. If this generated code is subsequently compiled, loaded, or executed, the attacker's code runs within the security context of the build environment or the consuming application.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation can lead to arbitrary code execution within the developer's build environment or the application consuming the generated client. This impacts any project relying on Kiota to generate Java or PHP clients from untrusted or tampered OpenAPI specifications. The vulnerability specifically affects the \u003ccode\u003eMicrosoft.OpenApi.Kiota\u003c/code\u003e and \u003ccode\u003eMicrosoft.OpenApi.Kiota.Builder\u003c/code\u003e NuGet packages. Organizations using automated CI/CD pipelines to generate SDKs from external OpenAPI sources are at the highest risk, as the injection occurs at the generation phase.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to Kiota version 1.35.0 or later to apply the fix, which properly neutralizes comment delimiters and updates the sanitization order for Java.\u003c/li\u003e\n\u003cli\u003eAfter upgrading, regenerate all clients previously created with vulnerable versions of Kiota.\u003c/li\u003e\n\u003cli\u003eImplement a policy to only generate clients from trusted, integrity-protected OpenAPI descriptions in build environments.\u003c/li\u003e\n\u003cli\u003eReview generated Java and PHP source code for unauthorized modifications before committing to version control or deploying to production environments.\u003c/li\u003e\n\u003cli\u003eRestrict access to build environments and minimize the privileges/secrets available to generation and CI/CD pipelines.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T18:48:19Z","date_published":"2026-10-06T18:48:19Z","id":"https://feed.craftedsignal.io/briefs/2026-10-kiota-code-injection/","summary":"The Kiota Java and PHP generators are vulnerable to a code injection attack where malicious OpenAPI descriptions can lead to the generation of attacker-controlled source code due to improper sanitization of block-comment delimiters.","title":"Kiota Java and PHP Code Injection via OpenAPI Sanitization Bypass","url":"https://feed.craftedsignal.io/briefs/2026-10-kiota-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:microsoft:kiota:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}