CVE-2026-54661

HIGH

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

Title source: cna
STIX 2.1

Description

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlled OpenAPI spec to inject code that executes when new HttpClient() or new Api() is constructed. This issue is fixed in version 13.12.2.

Scores

CVSS v3 8.3
EPSS 0.0027
EPSS Percentile 19.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1336 CWE-74 CWE-94
Status published
Products (2)
acacode/swagger-typescript-api < 13.12.2
npm/swagger-typescript-api 0 - 13.12.2npm
Published Jul 29, 2026
Tracked Since Jul 29, 2026