CVE-2026-54661

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.ejs interpolates servers[0].url from src/code-gen-process.ts into the HttpClient constructor without escaping, allowing an attacker-controlled OpenAPI spec to inject code that executes when new HttpClient() or new Api() is constructed. This issue is fixed in version 13.12.2.
Configurations

No configuration.

History

29 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-29 15:16

Updated : 2026-07-30 19:23


NVD link : CVE-2026-54661

Mitre link : CVE-2026-54661

CVE.ORG link : CVE-2026-54661


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine