PT-2026-50683 · Npm · Swagger-Typescript-Api
CVE-2026-54666
·
Published
2026-06-18
·
Updated
2026-07-29
CVSS v3.1
8.3
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
swagger-typescript-api versions prior to 13.12.2
Description
swagger-typescript-api fails to properly escape OpenAPI path keys when passing them through the
parseRouteName() function to the procedure-call.ejs templates. This allows an attacker who controls the OpenAPI specification to inject malicious JavaScript expressions using ${...} syntax into the generated API client. When a developer calls the affected generated method, the injected code is executed with the full privileges of the process, potentially leading to unauthorized file access, data exfiltration, or remote code execution.Recommendations
Update swagger-typescript-api to version 13.12.2 or later.
Exploit
Fix
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Swagger-Typescript-Api