High severityNVD Advisory· Published Jul 29, 2026· Updated Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
CVE-2026-54661
Description
swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlled OpenAPI spec to inject code that executes when new HttpClient() or new Api() is constructed. This issue is fixed in version 13.12.2.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
swagger-typescript-apinpm | < 13.12.2 | 13.12.2 |
Affected products
1- Range: <13.12.2
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-38c3-wv3c-v3xjghsaADVISORY
- github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9deghsax_refsource_MISCWEB
- github.com/acacode/swagger-typescript-api/pull/1779ghsax_refsource_MISCWEB
- github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2ghsax_refsource_MISCWEB
- github.com/acacode/swagger-typescript-api/security/advisories/GHSA-38c3-wv3c-v3xjghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.