GHSA-jqwh-526h-c92j

Suggest an improvement
Source
https://github.com/advisories/GHSA-jqwh-526h-c92j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jqwh-526h-c92j/GHSA-jqwh-526h-c92j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jqwh-526h-c92j
Aliases
Published
2026-07-24T15:46:46Z
Modified
2026-08-17T15:00:08Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
Details

Impact

The Kiota PHP code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI fields (e.g. description, default values, and property names) directly into PHP double-quoted string literals without properly escaping the $ character. Since PHP evaluates string interpolation expressions like "${expr}", "$var", and "{$obj->prop}" within double-quoted strings at runtime, an attacker who controls an OpenAPI specification file can inject arbitrary PHP code into generated model and request-builder classes.

Who is impacted

Developers using Kiota to generate PHP API clients from external or untrusted OpenAPI specifications

Teams with CI/CD pipelines configured to automatically regenerate client code from remote specs

Applications that deploy generated PHP code to production servers

Vulnerability details

Affected component: StringExtensions.cs

Root cause: The shared SanitizeDoubleQuote() function in Writers/StringExtensions.cs does not escape the $ character. As a result, any schema-derived string emitted as a PHP double-quoted literal preserves $-prefixed interpolation constructs (${...}, $var, {$...}) verbatim, which PHP evaluates at runtime instead of treating as literal text. This is the same class of code-generation literal-injection flaw previously fixed for the Ruby generator (# interpolation), recurring here as a missed variant for PHP's $ interpolation in the sibling sanitizer helper.

Attack vectors

OpenAPI description and default fields in schema properties

Property wire-name keys embedded in deserializer/serializer methods

Any schema-derived string embedded in PHP double-quoted literals

Severity: Critical when generated code reaches production; High for CI/CD environments with access to production secrets; Medium for public third-party specs; Low for developer-controlled specs.

Patches

#7863

Workarounds

If you cannot upgrade immediately:

  1. Audit and sanitize OpenAPI specifications: Review all OpenAPI specification files for any descriptions, default values, or property names containing the $ character. Remove or replace any suspicious strings before code generation.
  2. Code review of generated files: Implement mandatory code review of all generated PHP files before merging into any branch. Look for double-quoted strings containing ${, $var, or {$ patterns.
  3. Restrict specification sources: Only consume OpenAPI specifications from trusted internal sources. Avoid automatic code generation from external or third-party APIs until this patch is applied.
  4. Isolate generated code from production: Do not deploy generated PHP models to production environments unless the specification source has been verified and reviewed.
  5. Manual escaping (temporary): If regeneration is not possible, manually inspect and edit generated files to escape any $ characters in double-quoted string literals (replace $ with \$).

Remediation

Upgrade Kiota to 1.29.1, 1.32.4, or later.

Regenerate/refresh existing generated clients as a precaution:

Refreshing generated clients ensures previously generated vulnerable code is replaced with hardened output.

Database specific
{
    "cwe_ids": [
        "CWE-94"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-24T15:46:46Z",
    "nvd_published_at": "2026-07-16T15:16:35Z",
    "severity": "HIGH"
}
References

Affected packages

NuGet
Microsoft.OpenApi.Kiota

Package

Name
Microsoft.OpenApi.Kiota
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.OpenApi.Kiota

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.30.0
Fixed
1.32.4

Affected versions

1.*
1.30.0
1.31.0
1.31.1
1.32.0
1.32.1
1.32.2
1.32.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jqwh-526h-c92j/GHSA-jqwh-526h-c92j.json"
Microsoft.OpenApi.Kiota.Builder

Package

Name
Microsoft.OpenApi.Kiota.Builder
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.OpenApi.Kiota.Builder

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.30.0
Fixed
1.32.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jqwh-526h-c92j/GHSA-jqwh-526h-c92j.json"
Microsoft.OpenApi.Kiota

Package

Name
Microsoft.OpenApi.Kiota
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.OpenApi.Kiota

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.29.1

Affected versions

0.*
0.1.0-preview
0.1.1-preview
0.1.2-preview
0.1.3-preview
0.2.0-preview
0.2.1-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
0.8.3-preview
0.9.0-preview
0.10.0-preview
0.11.0-preview
0.11.1-preview
1.*
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0
1.24.0
1.24.1
1.24.2
1.24.3
1.25.1
1.26.0
1.26.1
1.27.0
1.28.0
1.29.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jqwh-526h-c92j/GHSA-jqwh-526h-c92j.json"
Microsoft.OpenApi.Kiota.Builder

Package

Name
Microsoft.OpenApi.Kiota.Builder
View open source insights on deps.dev
Purl
pkg:nuget/Microsoft.OpenApi.Kiota.Builder

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.29.1

Affected versions

0.*
0.2.0-preview
0.3.0-preview
0.4.0-preview
0.5.0-preview
0.5.1-preview
0.6.0-preview
0.7.1-preview
1.*
1.0.0
1.0.1
1.1.0
1.1.1
1.1.2
1.1.3
1.2.0
1.2.1
1.3.0
1.4.0
1.5.0
1.5.1
1.6.1
1.7.0
1.8.0
1.8.1
1.8.2
1.9.0
1.9.1
1.10.0
1.10.1
1.11.0
1.11.1
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.19.0
1.19.1
1.20.0
1.21.0
1.22.0
1.22.1
1.22.2
1.22.3
1.23.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-jqwh-526h-c92j/GHSA-jqwh-526h-c92j.json"