Sceawere

Vulnerability Detail

CVE-2026-105796UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Kiota Documentation Comment Injection

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
10h ago
Vendor
microsoft
Product
kiota
Attack Type
CWE-94: Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Kiota is an OpenAPI based HTTP Client code generator. From 0.5.0 until 1.35.0, Kiota's Java and PHP documentation-comment sanitizers delete block-comment terminators rather than neutralizing them, allowing overlapping characters to reform a terminator and place attacker-controlled OpenAPI text outside a generated documentation comment. The Java sanitizer also removes non-ASCII characters after deleting terminators, which can create a new terminator during normalization. Exploitation requires a developer or build pipeline to generate source from the malicious description and then compile and load the Java output or load the PHP output, after which injected code executes in the consuming application or build environment context. The version range is based on the Java defect and does not assert that PHP generation existed in every affected release. This issue is fixed in version 1.35.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-06T15:17:16.590Z",
  "pubdate": "2026-10-06T15:17:16.590Z",
  "executiveSummary": "Kiota versions 0.5.0 through 1.35.0 are affected by an improper neutralization of input during code generation, specifically within documentation-comment sanitizers.\nThe vulnerability allows an attacker to manipulate OpenAPI description files to break out of generated documentation comments, enabling the injection of arbitrary code into the resulting source files.\nThis flaw impacts both Java and PHP code generation, posing a significant risk to the software supply chain.\nExploitation requires an attacker to provide a malicious OpenAPI description file to a developer or automated build pipeline.\nOnce the malicious source code is generated, the injected payload executes within the context of the consuming application or the build environment upon compilation or execution.\nThis represents a critical security risk as it could lead to unauthorized code execution, data exfiltration, or complete system compromise depending on the privileges of the build process or the application environment.",
  "technicalDetails": "The vulnerability originates from a flawed implementation of documentation-comment sanitization logic within the Kiota code generation engine. Specifically, the sanitizers for Java and PHP fail to properly neutralize block-comment terminators (e.g., '*/').\nInstead of neutralizing these sequences, the sanitizer deletes the terminator characters in a way that allows surrounding characters to coalesce and form a new, valid terminator sequence. By strategically crafting the OpenAPI description, an attacker can prematurely close a comment block, thereby injecting arbitrary code into the source file.\nIn the Java implementation, the vulnerability is compounded by a secondary normalization process that removes non-ASCII characters. If a terminator is deleted, the subsequent character normalization can shift remaining data into a configuration that reassembles into a syntactically valid block-comment terminator, further facilitating the breakout.\nThe attack flow follows a specific progression: 1) An attacker submits a malicious OpenAPI description file containing embedded payload strings formatted to trigger the improper sanitization. 2) The Kiota tool processes this file, generating source code where the attacker's payload is positioned outside the intended documentation block due to the premature termination of the comment. 3) The generated source code is either compiled (in the case of Java) or directly loaded (in the case of PHP) by the downstream application or build process. 4) The injected instructions are interpreted as valid code rather than documentation comments, leading to unauthorized execution.\nThe impact is significant because the malicious code inherits the privilege level of the build environment or the execution context of the consuming application. Because this happens at the source-generation phase, it bypasses standard application-level security controls, effectively poisoning the project's source code base."
}
CVE-2026-105796: Kiota Documentation Comment Injection (HIGH Severity, CVSS: 8.8) | Sceawere