PT-2026-34560 · Kiota · Kiota

Thanatos Tian

·

Published

2026-04-14

·

Updated

2026-05-17

·

CVE-2026-41134

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kiota versions prior to 1.31.1
Description Kiota is an OpenAPI based HTTP Client code generator. A code-generation literal injection exists in multiple writer sinks, including serialization/deserialization keys, path/query parameter mappings, URL template metadata, enum/property metadata, and default value emission. When malicious values from an OpenAPI description are emitted into generated source without context-appropriate escaping, an attacker can break out of string literals and inject additional code into generated clients. This is practically exploitable when the OpenAPI description used for generation is from an untrusted source or has been compromised.
Recommendations Upgrade to version 1.31.1 or later and regenerate or refresh existing generated clients. Generate clients only from trusted, integrity-protected API descriptions.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41134
GHSA-2HX3-VP6R-MG3F

Affected Products

Kiota