CVE-2026-54663

MEDIUM

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

Title source: cna
STIX 2.1

Description

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpRemoteSchemasCache resolves external $ref URLs and fetchRemoteSchemaDocument uses isHttpUrl to fetch any http or https target without private IP, redirect, DNS rebinding, or same-origin validation, allowing an attacker-controlled OpenAPI spec to make the generator issue requests to internal or link-local services. This issue is fixed in version 13.12.2.

Scores

CVSS v3 6.1
EPSS 0.0018
EPSS Percentile 7.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-20 CWE-441 CWE-918
Status published
Products (2)
acacode/swagger-typescript-api < 13.12.2
npm/swagger-typescript-api 0 - 13.12.2npm
Published Jul 29, 2026
Tracked Since Jul 29, 2026