CVE-2026-54666

HIGH

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

Title source: cna
STIX 2.1

Description

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts passes OpenAPI path keys through parseRouteName to templates/default/procedure-call.ejs and templates/modular/procedure-call.ejs without escaping JavaScript template literal interpolation, allowing an attacker-controlled path containing ${...} to execute when the generated method is called. This issue is fixed in version 13.12.2.

Scores

CVSS v3 8.3
EPSS 0.0029
EPSS Percentile 20.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-1336 CWE-74 CWE-94
Status published
Products (2)
acacode/swagger-typescript-api < 13.12.2
npm/swagger-typescript-api 0 - 13.12.2npm
Published Jul 29, 2026
Tracked Since Jul 29, 2026