High severity8.3NVD Advisory· Published Jul 29, 2026· Updated Jul 30, 2026
CVE-2026-54661
CVE-2026-54661
Description
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlled OpenAPI spec to inject code that executes when new HttpClient() or new Api() is constructed. This issue is fixed in version 13.12.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
swagger-typescript-apinpm | < 13.12.2 | 13.12.2 |
Affected products
1- Range: <13.12.2
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-38c3-wv3c-v3xjghsaADVISORY
- github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9denvdWEB
- github.com/acacode/swagger-typescript-api/pull/1779nvdWEB
- github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2nvdWEB
- github.com/acacode/swagger-typescript-api/security/advisories/GHSA-38c3-wv3c-v3xjnvdWEB
News mentions
0No linked articles in our index yet.