VYPR
High severityNVD Advisory· Published Jul 29, 2026· Updated Jul 29, 2026

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

CVE-2026-54661

Description

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlled OpenAPI spec to inject code that executes when new HttpClient() or new Api() is constructed. This issue is fixed in version 13.12.2.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
swagger-typescript-apinpm
< 13.12.213.12.2

Affected products

1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.