-
Notifications
You must be signed in to change notification settings - Fork 720
Expand file tree
/
Copy pathGHSA-3hrf-2gc2-mx32.json
More file actions
130 lines (130 loc) · 5.05 KB
/
Copy pathGHSA-3hrf-2gc2-mx32.json
File metadata and controls
130 lines (130 loc) · 5.05 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
{
"schema_version": "1.4.0",
"id": "GHSA-3hrf-2gc2-mx32",
"modified": "2026-08-17T14:52:02Z",
"published": "2026-07-24T15:30:47Z",
"aliases": [
"CVE-2026-59860"
],
"summary": "Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection",
"details": "### Summary\n\nKiota versions **prior to 1.32.3** are affected by a code-generation injection vulnerability in the C# XML documentation-comment sink (the `description`, `externalDocs` label, and `externalDocs` link fields emitted as `/// …` comments).\n\nWhen text from an OpenAPI description is written into single-line XML doc comments without stripping newline and Unicode line-terminator characters, an attacker can break out of the `///` comment line and inject additional code into generated C# clients.\n\n## Impact and Preconditions\n\nThis issue is only practically exploitable when:\n\n1. the OpenAPI description used for generation is from an **untrusted source**, or\n2. a normally trusted OpenAPI description has been **compromised/tampered with**.\n\nThe injected code is compiled (and may execute) when the developer or CI **builds** the generated client. If you only generate from trusted, integrity-protected API descriptions, risk is significantly reduced.\n\n## Affected Versions\n\n- **Affected:** all versions **< 1.32.3**\n- **Fixed: 1.32.3** and later\n\n## Illustrative Exploit Example\n\n### Example OpenAPI fragment (malicious description)\n\n```yaml\nopenapi: 3.0.1\ninfo:\n title: Exploit Demo\n version: 1.0.0\n description: |-\n Legitimate summary text\n public static class Pwned { static Pwned() { System.Diagnostics.Process.Start(\"calc.exe\"); } }\n```\n\nThe newline inside `description` (also exploitable via `\\r`, U+0085, U+2028, U+2029) terminates the doc-comment line.\n\n### Example generated C# snippet before fix (illustrative)\n\n```csharp\n/// Legitimate summary text\npublic static class Pwned { static Pwned() { System.Diagnostics.Process.Start(\"calc.exe\"); } }\n```\n\nThe injected payload escapes the intended `///` comment context and introduces attacker-controlled statements in generated code.\n\n> Note: this exploit is not limited to the `description` field, but may also impact the `externalDocs` label and link text and other doc-comment-derived locations.\n\n## Remediation\n\n1. Upgrade Kiota to **1.32.3 or later**.\n2. Regenerate/refresh existing generated clients as a precaution:\n\nRefreshing generated clients ensures previously generated vulnerable code is replaced with hardened output. The fix (PR microsoft/kiota#7831) strips `\\r`, `\\n`, `\\u0085`, `\\u2028`, `\\u2029` (and normalizes tabs) from description, label, and link text before emitting doc comments.",
"severity": [
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
}
],
"affected": [
{
"package": {
"ecosystem": "NuGet",
"name": "Microsoft.OpenApi.Kiota"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.30.0"
},
{
"fixed": "1.32.3"
}
]
}
]
},
{
"package": {
"ecosystem": "NuGet",
"name": "Microsoft.OpenApi.Kiota.Builder"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.30.0"
},
{
"fixed": "1.32.3"
}
]
}
]
},
{
"package": {
"ecosystem": "NuGet",
"name": "Microsoft.OpenApi.Kiota.Builder"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.29.1"
}
]
}
]
},
{
"package": {
"ecosystem": "NuGet",
"name": "Microsoft.OpenApi.Kiota"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "1.29.1"
}
]
}
]
}
],
"references": [
{
"type": "WEB",
"url": "https://github.com/microsoft/kiota/security/advisories/GHSA-3hrf-2gc2-mx32"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-59860"
},
{
"type": "WEB",
"url": "https://github.com/microsoft/kiota/pull/7831"
},
{
"type": "WEB",
"url": "https://github.com/microsoft/kiota/commit/ebb632db90aa8e3c20949337d9faa2720d64ca44"
},
{
"type": "PACKAGE",
"url": "https://github.com/microsoft/kiota"
},
{
"type": "WEB",
"url": "https://github.com/microsoft/kiota/releases/tag/v1.32.3"
}
],
"database_specific": {
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed": true,
"github_reviewed_at": "2026-07-24T15:30:47Z",
"nvd_published_at": "2026-07-16T15:16:35Z"
}
}