Kiota is an OpenAPI based HTTP Client code generator
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby double-quoted literals without escaping #, allowing attacker-controlled #{expr}, #$var, or #@var interpolation markers to inject arbitrary Ruby code into generated model classes. This issue is fixed in version 1.32.0.
CVSS Score
7.5
HIGH
Published
16 Jul 2026 15:16
Modified
29 Jul 2026 20:17
Source
CIRCL
CVSS v3 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Complexity
Low
Privileges
None
Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Weaknesses (CWE)
CWE-94
Affected Systems
No vendor data available.
External Links
KEV Status
Not in CISA KEV catalog