Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when kiota generate ran without -c/--class-name, allowing an attacker-controlled or compromised OpenAPI description to write generated source outside the -o output directory and inject arbitrary text into generated class or namespace declarations. This issue is fixed in version 1.29.1 and 1.32.5 by GenerationConfiguration.SanitizeClientClassName and SanitizeClientNamespaceName.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-22",
"CWE-94"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59866.json"
}{
"extracted_events": [
{
"introduced": "1.30.0"
},
{
"fixed": "1.31.1"
},
{
"introduced": "0"
},
{
"fixed": "1.29.1"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59866.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"66609017551477010826143835577406265593",
"35496344713004664179944048284480170529",
"147500007851372202392601133532187874810",
"240753228186878202917022054237087631710",
"322801780681153563118919792465691120440",
"105331927903652750006918956054969541779",
"92754106178057991798446179728179208061",
"253209821667215414607528288804099395645",
"250008073155348665397373185331785853495",
"64797852886090781921647040874546962214"
],
"threshold": 0.9
},
"id": "CVE-2026-59866-0255b0db",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/microsoft/kiota/commit/70cd8bcba3ff1815f93187f3eb80ef96fd194d46",
"target": {
"file": "it/java/gh/src/test/java/GHAPITest.java"
}
}
]
"2026-08-19T12:09:54Z"