PT-2026-50683 · Npm · Swagger-Typescript-Api

CVE-2026-54666

·

Published

2026-06-18

·

Updated

2026-07-29

CVSS v3.1

8.3

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions swagger-typescript-api versions prior to 13.12.2
Description swagger-typescript-api fails to properly escape OpenAPI path keys when passing them through the parseRouteName() function to the procedure-call.ejs templates. This allows an attacker who controls the OpenAPI specification to inject malicious JavaScript expressions using ${...} syntax into the generated API client. When a developer calls the affected generated method, the injected code is executed with the full privileges of the process, potentially leading to unauthorized file access, data exfiltration, or remote code execution.
Recommendations Update swagger-typescript-api to version 13.12.2 or later.

Exploit

Fix

Special Elements Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54666
GHSA-W284-33MX-6G9V

Affected Products

Swagger-Typescript-Api