PT-2026-34560 · Kiota · Kiota
Thanatos Tian
·
Published
2026-04-14
·
Updated
2026-05-17
·
CVE-2026-41134
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kiota versions prior to 1.31.1
Description
Kiota is an OpenAPI based HTTP Client code generator. A code-generation literal injection exists in multiple writer sinks, including serialization/deserialization keys, path/query parameter mappings, URL template metadata, enum/property metadata, and default value emission. When malicious values from an OpenAPI description are emitted into generated source without context-appropriate escaping, an attacker can break out of string literals and inject additional code into generated clients. This is practically exploitable when the OpenAPI description used for generation is from an untrusted source or has been compromised.
Recommendations
Upgrade to version 1.31.1 or later and regenerate or refresh existing generated clients.
Generate clients only from trusted, integrity-protected API descriptions.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kiota