CVE-2026-41134Disclosure(microsoft / kiota)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.29.1 and 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example: serialization/deserialization keys, path/query parameter mappings, URL template metadata, enum/property metadata, and default value emission). When malicious values from an OpenAPI description are emitted into generated source without context-appropriate escaping, an attacker can break out of string literals and inject additional code into generated clients. This issue is only practically exploitable when the OpenAPI description used for generation is from an untrusted source, or a normally trusted OpenAPI description has been compromised/tampered with. Only generating from trusted, integrity-protected API descriptions significantly reduces the risk. To remediate the issue, upgrade Kiota to 1.29.1, 1.31.1, or later and regenerate/refresh existing generated clients as a precaution. Refreshing generated clients ensures previously generated vulnerable code is replaced with hardened output.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kiota

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-22); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
kiota

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-22: 2Mentions · 2026-04-23: 1Mentions · 2026-05-17: 1Technical Details · 2026-04-22: 2Technical Details · 2026-04-23: 1Technical Details · 2026-05-17: 104-2204-2305-17
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-222
Disclosure2
2026-04-231
Disclosure1
2026-05-171
Disclosure1
Full discourse4 posts
  • Israel@f1tym1
    Disclosure

    CVE-2026-41134 | Microsoft kiota up to 1.31.0 Query Parameter code injection (GHSA-2hx3-vp6r-mg3f) https://ift.tt/FdaqDO3 A vulnerability classified as critical was found in Microsoft kiota up to 1.31.0. Affected is an unknown function of the component Query Parameter Handler.…

    Post summary

    The tweet announces a critical query‑parameter code injection vulnerability in Microsoft kiota through v1.31.0, providing only the CVE and severity but no PoC, exploit, patch, or evidence of live attacks.

    0000059
    974 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41134 Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer si… https://www.cve.org/CVERecord?id=CVE-2026-41134

    Post summary

    CVE-2026-41134 is a code‑generation literal injection vulnerability that affects Kiota versions earlier than 1.31.1; the post links to the CVE record but does not detail a PoC, exploit, or patch.

    00000124
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41134 Kiota is an OpenAPI based HTTP Client code generator. Versions prior to 1.31.1 are affected by a code-generation literal injection vulnerability in multiple writer sinks (for example https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41134

    Post summary

    The text reports that Kiota versions before 1.31.1 are vulnerable to a code-generation literal injection (CVE‑2026‑41134), providing specific technical details but no PoC, exploit code, active exploitation, or patch information.

    0000071
    4.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    ⚠️ CVE-2026-41134: Kiota: ... Poisoned OpenAPI specs can inject arbitrary code into generated HTTP clients - supply chain nightmare waiting to happen. #SupplyChain #CodeGen. https://zerodaysignal.com/vulnerability/CVE-2026-41134 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a new supply‑chain vulnerability (CVE‑2026‑41134) in Kiota, where poisoned OpenAPI specifications can lead to arbitrary code execution in generated HTTP clients, and links to a vulnerability detail page.

    00000122
    218 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftkiota---

Explore more