Listen to this Post
CVE-2026-105796 is a code injection vulnerability in Microsoft Kiota, an OpenAPI-based HTTP client code generator.The flaw resides in the Java and PHP documentation-comment sanitizers, which from version 0.5.0 through 1.34.1 delete block-comment terminators instead of neutralizing them.When an attacker controls or tampers with an OpenAPI description consumed by Kiota, the sanitizer’s deletion-based approach allows a terminator to reform from overlapping characters or through subsequent normalization steps.The Java sanitizer compounds the issue by removing non-ASCII characters after deleting terminators, which can itself create a new terminator sequence during the normalization process.This means a carefully crafted OpenAPI description can cause Kiota to emit attacker-controlled Java or PHP source code outside the intended generated documentation comment block.The injected code is not executed merely because Kiota reads the description; exploitation requires a developer or build pipeline to generate a client from the malicious description and then compile and load the Java output, or load the PHP output.Once that compilation or loading step occurs, the injected code executes in the consuming application’s or build environment’s security context.The version range 0.5.0 to 1.34.1 reflects the Java normalization-order defect, which includes the separate 1.29.1 security-backport release; the PHP delimiter-reformation variant is also present in 1.34.1 and 1.29.1.Version 1.35.0 fixes both variants by neutralizing block-comment delimiters rather than deleting them, and by performing Java delimiter neutralization after non-ASCII normalization.Until upgrading, the only reliable mitigation is to generate clients exclusively from trusted, integrity-protected OpenAPI descriptions, review generated Java and PHP source before compiling or loading, and restrict the privileges available to generation and build environments.
DailyCVE Form:
Platform: Kiota
Version: 0.5.0-1.34.1
Vulnerability: Code Injection
Severity: High
date: 2026-10-06
Prediction: 1.35.0 (released)
What Undercode Say:
Check installed Kiota version dotnet tool list --global | grep kiota Generate a Java client from an OpenAPI description kiota generate -l Java -d malicious-spec.yaml -o ./generated-client Generate a PHP client from an OpenAPI description kiota generate -l PHP -d malicious-spec.yaml -o ./generated-client Inspect generated Java documentation comments for escaped terminators grep -n "\/" ./generated-client/src/main/java//.java Inspect generated PHP documentation comments for escaped terminators grep -n "\/" ./generated-client/src//.php Verify that non-ASCII characters are neutralized, not removed after terminator deletion grep -P '[^\x00-\x7F]' ./generated-client/src/main/java//.java
Exploit: (Educational Purposes!)
A malicious OpenAPI description can embed a sequence such as `/\nSystem.exit(1);\n/` within a description field. The Java sanitizer deletes the first /, but the deletion joins the preceding “ with the following `/` during normalization, reforming `/` and prematurely closing the documentation comment. Subsequent text is emitted as executable Java code. For PHP, overlapping characters in the description can similarly reform a comment terminator after deletion. The attacker does not need code execution on the Kiota generation host; the payload executes only when the generated client is compiled or loaded by the consuming application or build pipeline.
Protection: from this CVE
Upgrade to Kiota 1.35.0 or later and regenerate all affected clients. Generate clients only from OpenAPI descriptions that are trusted and integrity-protected. Review all generated Java and PHP source code before compiling, loading, or deploying it. Restrict the privileges and secrets available to generation and build environments so that even if injection succeeds, the blast radius is minimized. Do not rely on the fixes for GHSA-jqwh-526h-c92j or GHSA-3hrf-2gc2-mx32, as those address different sinks and do not neutralize Java/PHP block-comment delimiter reformation.
Impact:
An attacker who controls or tampers with an OpenAPI description can cause Kiota to emit attacker-controlled Java or PHP source outside a generated documentation comment. When a developer or build pipeline compiles and loads the Java output, or loads the PHP output, the injected code executes in the consuming application’s or build environment’s security context. This can lead to arbitrary code execution, data exfiltration, backdoor installation, or full compromise of the build pipeline and any secrets it holds. The vulnerability is rated High with a CVSS 3.1 base score of 8.8.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

