BRIEFING NOTE Kiota versions prior to 1.31.1 contain a code-generation literal injection vulnerability that allows attackers to inject malicious code into generated HTTP clients. The flaw exists across multiple generation sinks including serialization keys, parameter mappings, URL metadata, and default values. This OpenAPI-based code generator is vulnerable when processing untrusted or compromised API descriptions, enabling attackers to break out of string literals and inject additional source code into the generated output. The vulnerability requires network access and low attack complexity, as it exploits inadequate context-appropriate escaping of malicious values from OpenAPI descriptions during code generation. The primary attack vector involves supplying a compromised or malicious OpenAPI specification, making this a supply chain risk. The practical impact is significant if generated clients are deployed without review, potentially allowing attackers to execute arbitrary code within applications using the generated clients. This vulnerability has not yet been observed in active exploitation campaigns, and there is no indication of publicly available exploit code. However, the issue is tracked on the Known Exploited Vulnerabilities list as active, suggesting elevated concern within the community. Mitigation requires immediate upgrade to Kiota 1.31.1 or later and regeneration of all previously generated clients to replace potentially vulnerable code with hardened output.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.31.1CPE matchmatch criteria | cpe:2.3:a:microsoft:kiota:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.