CVE-2026-59866: Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceName values without identifier or path sanitization as both generated client class or namespace names and generated output path components when `kiota generate` ran without -c/--class-name, allowing an attacker-controlled or compromised OpenAPI description to write generated source outside the -o output directory and inject arbitrary text into generated class or namespace declarations. This issue is fixed in version 1.32.5 by GenerationConfiguration.SanitizeClientClassName and SanitizeClientNamespaceName.
Security readout for executives and security teams
Plain-English summary
Kiota versions before 1.32.5 can trust naming metadata from an OpenAPI description too much. If a malicious or compromised API description is used to generate a client, it may cause files to be written outside the intended output folder and inject text into generated source declarations.
Executive priority
Treat as urgent for teams using Kiota in automated generation pipelines. The issue can affect source integrity, but risk is concentrated where untrusted API descriptions enter build or developer workflows.
Technical view
The issue affects Microsoft Kiota before 1.32.5. Unsanitized x-ms-kiota-info clientClassName and clientNamespaceName values were used as identifiers and output path components when generation ran without -c/--class-name. The fix adds sanitization via GenerationConfiguration.SanitizeClientClassName and SanitizeClientNamespaceName.
Likely exposure
Exposure is likely in developer workstations, CI jobs, or build systems that run kiota generate against OpenAPI descriptions from external, partner, generated, or otherwise weakly controlled sources.
Exploitation context
The bundle does not show KEV listing or confirmed active exploitation. Practical risk depends on whether an attacker can influence the OpenAPI description consumed by Kiota generation workflows.
Researcher notes
Public sources identify CWE-22 and CWE-94 impacts, with CVSS 4.0 score 9.3. The available bundle names affected versions and the fix, but does not provide evidence of active exploitation.
Mitigation direction
Upgrade Microsoft Kiota to version 1.32.5 or later.
Pin Kiota versions in CI and developer tooling.
Avoid generating clients from untrusted or unreviewed OpenAPI descriptions.
Use explicit class-name configuration where upgrade is delayed.
Check Microsoft advisory and release notes for any additional guidance.
Validation and detection
Inventory Kiota versions across CI, developer images, and repositories.
Identify workflows running kiota generate without -c/--class-name.
Review OpenAPI description sources for external or weakly trusted inputs.
Check generated output trees for unexpected paths or source changes.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-22: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Code execution and unsafe deserialization weaknesses often justify reviewing execution behavior and process telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
5Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.