Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41134

26
FAUCET Score

BRIEFING NOTE Kiota versions prior to 1.31.1 contain a code-generation literal injection vulnerability that allows attackers to inject malicious code into generated HTTP clients. The flaw exists across multiple generation sinks including serialization keys, parameter mappings, URL metadata, and default values. This OpenAPI-based code generator is vulnerable when processing untrusted or compromised API descriptions, enabling attackers to break out of string literals and inject additional source code into the generated output. The vulnerability requires network access and low attack complexity, as it exploits inadequate context-appropriate escaping of malicious values from OpenAPI descriptions during code generation. The primary attack vector involves supplying a compromised or malicious OpenAPI specification, making this a supply chain risk. The practical impact is significant if generated clients are deployed without review, potentially allowing attackers to execute arbitrary code within applications using the generated clients. This vulnerability has not yet been observed in active exploitation campaigns, and there is no indication of publicly available exploit code. However, the issue is tracked on the Known Exploited Vulnerabilities list as active, suggesting elevated concern within the community. Mitigation requires immediate upgrade to Kiota 1.31.1 or later and regeneration of all previously generated clients to replace potentially vulnerable code with hardened output.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.31.1CPE matchmatch criteria
cpe:2.3:a:microsoft:kiota:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.3HIGH

CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.42%
Probability of exploitation in next 30 days
EPSS Percentile
34.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0042 is in the 75th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

nugetpatch availablevia ghsa
Product: kiotaFixed in: 1.31.1
nugetpatch availablevia ghsa
Product: Microsoft.OpenApi.KiotaFixed in: 1.31.1
nugetpatch availablevia ghsa
Product: Microsoft.OpenApi.Kiota.BuilderFixed in: 1.31.1
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

nugetGHSA-2hx3-vp6r-mg3fhigh

Kiota: Code Generation Literal Injection

Apr 14, 2026

References

github.com / microsoft/kiota/security/advisories/GHSA-2hx3-vp6r-mg3f
ExploitVendor Advisory