ESC
Type to search CVEs in real-time
Enter open Esc close Ctrl K toggle

CVE-2026-59861

HIGH Export PDF

Kiota is an OpenAPI based HTTP Client code generator

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.0, Kiota's Ruby generator embedded OpenAPI default fields, property names, and other schema-derived strings through CodeMethodWriter.cs and SanitizeForQuotedLiteral() in Writers/StringExtensions.cs into Ruby double-quoted literals without escaping #, allowing attacker-controlled #{expr}, #$var, or #@var interpolation markers to inject arbitrary Ruby code into generated model classes. This issue is fixed in version 1.32.0.

CVSS Score
7.5
HIGH
Published
16 Jul 2026 15:16
Modified
29 Jul 2026 20:17
Source
CIRCL

CVSS v3 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Complexity
Low
Privileges
None
Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Weaknesses (CWE)

CWE-94

Affected Systems

No vendor data available.

KEV Status

Not in CISA KEV catalog