PYPI · JULY 2026 · EARLY WARNING

Kiota Python Code Generator Vulnerable to Arbitrary Code Execution

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-7F3J-J7JJ-R3VRSeverity: HIGH

The Kiota Python code generator is reportedly vulnerable to a code generation literal injection issue that can lead to arbitrary code execution. Malicious OpenAPI specifications can cause arbitrary Python code to be emitted into generated model files, executing when the affected module is imported.

What happened

An early warning has been issued regarding a vulnerability in the Kiota Python code generator. The issue, tracked as GHSA-7F3J-J7JJ-R3VR, involves a code generation literal injection that can lead to arbitrary code execution. According to the advisory, malicious OpenAPI specifications can cause arbitrary Python code to be emitted into generated model files. This code is then executed when the affected module is imported. The vulnerability is under investigation, and it is recommended to avoid generating Python SDKs from untrusted OpenAPI specifications until a patch is available. For more details, consult the primary sources listed in the threat data.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If kiota is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats