CVE-2026-59861High· 7.5▾ TwilightMicrosoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
1.5%
1.5% → 2.0%
Code Generation Literal Injection in Kiota Ruby Generator Leads to Arbitrary Code Execution
The Kiota Ruby code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI default fields and property names directly into Ruby double-quoted string literals without properly escaping the # character. Since Ruby evaluates string interpolation expressions like #{expr}, #$var, and #@var within double-quoted strings at runtime, an attacker who controls an OpenAPI specification file can inject arbitrary Ruby code into generated model classes.
Developers using Kiota to generate Ruby API clients from external or untrusted OpenAPI specifications Teams with CI/CD pipelines configured to automatically regenerate client code from remote specs Applications that deploy generated Ruby code to production servers
Affected component: CodeMethodWriter.cs Root cause: The shared SanitizeForQuotedLiteral() function in Writers/StringExtensions.cs does not escape the # character
OpenAPI default fields in schema properties Property wire-name hash keys in deserializer/serializer methods Any schema-derived string embedded in Ruby double-quoted literals Severity: Critical when generated code reaches production; High for CI/CD environments with access to production secrets; Medium for public third-party specs; Low for developer-controlled specs.
https://github.com/microsoft/kiota/pull/7746
If you cannot upgrade immediately:
Upgrade Kiota to 1.32.0 or later. Regenerate/refresh existing generated clients as a precaution:
kiota update
Refreshing generated clients ensures previously generated vulnerable code is replaced with hardened output.
Microsoft.OpenAPI.Kiota < 1.32.0Microsoft.OpenAPI.Kiota.Builder < 1.32.0Upgrade to a patched release:
Microsoft.OpenAPI.Kiota 1.32.0Microsoft.OpenAPI.Kiota.Builder 1.32.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-59862High· 7.5Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
CVE-2026-59860HighMicrosoft Kiota: XML Doc-Comment Newline Breakout Code Injection
CVE-2026-59859HighMicrosoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
CVE-2026-59865CriticalMicrosoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
CVE-2026-59866HighMicrosoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
CVE-2025-14576High· 7.8Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick