Skip to content
Closed
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@
"CVE-2026-59859"
],
"summary": "Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator",
"details": "# Impact\n\nThe Kiota PHP code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI fields (e.g. `description`, default values, and property names) directly into PHP double-quoted string literals without properly escaping the `$` character. Since PHP evaluates string interpolation expressions like `\"${expr}\"`, `\"$var\"`, and `\"{$obj->prop}\"` within double-quoted strings at runtime, an attacker who controls an OpenAPI specification file can inject arbitrary PHP code into generated model and request-builder classes.\n\n# Who is impacted\n\nDevelopers using Kiota to generate PHP API clients from external or untrusted OpenAPI specifications\n\nTeams with CI/CD pipelines configured to automatically regenerate client code from remote specs\n\nApplications that deploy generated PHP code to production servers\n\n# Vulnerability details\n\nAffected component: `StringExtensions.cs`\n\nRoot cause: The shared `SanitizeDoubleQuote()` function in `Writers/StringExtensions.cs` does not escape the `$` character. As a result, any schema-derived string emitted as a PHP double-quoted literal preserves `$`-prefixed interpolation constructs (`${...}`, `$var`, `{$...}`) verbatim, which PHP evaluates at runtime instead of treating as literal text. This is the same class of code-generation literal-injection flaw previously fixed for the Ruby generator (`#` interpolation), recurring here as a missed variant for PHP's `$` interpolation in the sibling sanitizer helper.\n\n# Attack vectors\n\nOpenAPI `description` and default fields in schema properties\n\nProperty wire-name keys embedded in deserializer/serializer methods\n\nAny schema-derived string embedded in PHP double-quoted literals\n\nSeverity: Critical when generated code reaches production; High for CI/CD environments with access to production secrets; Medium for public third-party specs; Low for developer-controlled specs.\n\n# Patches\n\n[#7863](https://github.com/microsoft/kiota/pull/7863)\n\n# Workarounds\n\nIf you cannot upgrade immediately:\n\n1. Audit and sanitize OpenAPI specifications: Review all OpenAPI specification files for any descriptions, default values, or property names containing the `$` character. Remove or replace any suspicious strings before code generation.\n2. Code review of generated files: Implement mandatory code review of all generated PHP files before merging into any branch. Look for double-quoted strings containing `${`, `$var`, or `{$` patterns.\n3. Restrict specification sources: Only consume OpenAPI specifications from trusted internal sources. Avoid automatic code generation from external or third-party APIs until this patch is applied.\n4. Isolate generated code from production: Do not deploy generated PHP models to production environments unless the specification source has been verified and reviewed.\n5. Manual escaping (temporary): If regeneration is not possible, manually inspect and edit generated files to escape any `$` characters in double-quoted string literals (replace `$` with `\\$`).\n\n# Remediation\n\nUpgrade Kiota to 1.29.1, 1.32.4, or later.\n\nRegenerate/refresh existing generated clients as a precaution:\n\nRefreshing generated clients ensures previously generated vulnerable code is replaced with hardened output.",
"details": "# Impact\n\nThe Kiota PHP code generator is vulnerable to a code generation literal injection attack. The generator embeds string values from OpenAPI fields (e.g. `description`, default values, and property names) directly into PHP double-quoted string literals without properly escaping the `$` character. Since PHP evaluates string interpolation expressions like `\"${expr}\"`, `\"$var\"`, and `\"{$obj->prop}\"` within double-quoted strings at runtime, an attacker who controls an OpenAPI specification file can inject arbitrary PHP code into generated model and request-builder classes.\n\n# Who is impacted\n\nDevelopers using Kiota to generate PHP API clients from external or untrusted OpenAPI specifications\n\nTeams with CI/CD pipelines configured to automatically regenerate client code from remote specs\n\nApplications that deploy generated PHP code to production servers\n\n# Vulnerability details\n\nAffected component: `StringExtensions.cs`\n\nRoot cause: The shared `SanitizeDoubleQuote()` function in `Writers/StringExtensions.cs` does not escape the `$` character. As a result, any schema-derived string emitted as a PHP double-quoted literal preserves `$`-prefixed interpolation constructs (`${...}`, `$var`, `{$...}`) verbatim, which PHP evaluates at runtime instead of treating as literal text. This is the same class of code-generation literal-injection flaw previously fixed for the Ruby generator (`#` interpolation), recurring here as a missed variant for PHP's `$` interpolation in the sibling sanitizer helper.\n\n# Attack vectors\n\nOpenAPI `description` and default fields in schema properties\n\nProperty wire-name keys embedded in deserializer/serializer methods\n\nAny schema-derived string embedded in PHP double-quoted literals\n\nSeverity: Critical when generated code reaches production; High for CI/CD environments with access to production secrets; Medium for public third-party specs; Low for developer-controlled specs.\n\n# Patches\n\n[#7863](https://github.com/microsoft/kiota/pull/7863)\n\n# Workarounds\n\nIf you cannot upgrade immediately:\n\n1. Audit and sanitize OpenAPI specifications: Review all OpenAPI specification files for any descriptions, default values, or property names containing the `$` character. Remove or replace any suspicious strings before code generation.\n2. Code review of generated files: Implement mandatory code review of all generated PHP files before merging into any branch. Look for double-quoted strings containing `${`, `$var`, or `{$` patterns.\n3. Restrict specification sources: Only consume OpenAPI specifications from trusted internal sources. Avoid automatic code generation from external or third-party APIs until this patch is applied.\n4. Isolate generated code from production: Do not deploy generated PHP models to production environments unless the specification source has been verified and reviewed.\n5. Manual escaping (temporary): If regeneration is not possible, manually inspect and edit generated files to escape any `$` characters in double-quoted string literals (replace `$` with `\\$`).\n\n# Remediation\n\nUpgrade Kiota to 1.32.4 or later.\n\nRegenerate/refresh existing generated clients as a precaution:\n\nRefreshing generated clients ensures previously generated vulnerable code is replaced with hardened output.",
"severity": [
{
"type": "CVSS_V4",
Expand Down Expand Up @@ -56,7 +56,7 @@
{
"package": {
"ecosystem": "NuGet",
"name": "Microsoft.OpenApi.Kiota"
"name": "Microsoft.OpenApi.Kiota.Builder"
},
"ranges": [
{
Expand All @@ -75,7 +75,7 @@
{
"package": {
"ecosystem": "NuGet",
"name": "Microsoft.OpenApi.Kiota.Builder"
"name": "Microsoft.OpenApi.Kiota"
},
"ranges": [
{
Expand Down
Loading