CVE-2026-54662

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into the generated HttpClient baseUrl field without escaping, allowing an attacker-controlled OpenAPI spec to inject TypeScript static field code that executes when the generated fetch client module is imported. This issue is fixed in version 13.12.2.
Configurations

No configuration.

History

29 Jul 2026, 16:17

Type Values Removed Values Added
References () https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-hqj5-cw9f-rx67 - () https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-hqj5-cw9f-rx67 -

29 Jul 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-29 15:16

Updated : 2026-07-30 19:23


NVD link : CVE-2026-54662

Mitre link : CVE-2026-54662

CVE.ORG link : CVE-2026-54662


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine