Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, property names, and other schema-derived strings into PHP double-quoted literals through SanitizeDoubleQuote() in Writers/StringExtensions.cs without escaping $, allowing attacker-controlled ${...}, $var, or {$obj->prop} interpolation constructs to inject arbitrary PHP code into generated model and request-builder classes. This issue is fixed in version 1.29.1 and 1.32.4.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59859.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-94"
]
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "1.30.0"
},
{
"fixed": "1.31.1"
},
{
"introduced": "0"
},
{
"fixed": "1.29.1"
}
]
}
"2026-08-19T09:06:19Z"
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"66609017551477010826143835577406265593",
"35496344713004664179944048284480170529",
"147500007851372202392601133532187874810",
"240753228186878202917022054237087631710",
"322801780681153563118919792465691120440",
"105331927903652750006918956054969541779",
"92754106178057991798446179728179208061",
"253209821667215414607528288804099395645",
"250008073155348665397373185331785853495",
"64797852886090781921647040874546962214"
]
},
"signature_type": "Line",
"source": "https://github.com/microsoft/kiota/commit/70cd8bcba3ff1815f93187f3eb80ef96fd194d46",
"id": "CVE-2026-59859-0255b0db",
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "it/java/gh/src/test/java/GHAPITest.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59859.json"