


Perceptive Security
SOC/SIEM Consultancy

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.e…
Published:
28 July 2026 at 22:00:00
Alert date:
29 July 2026 at 16:02:53
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
A code injection vulnerability exists in swagger-typescript-api prior to version 13.12.2. The vulnerability resides in the axios-http-client.ejs template, which interpolates the servers[0].url value from an OpenAPI specification into the HttpClient constructor without proper escaping. An attacker who controls the OpenAPI spec can inject arbitrary code that executes when new HttpClient() or new Api() is instantiated. This represents a supply chain risk as developers consuming malicious or attacker-modified OpenAPI specs could have malicious code executed during API client generation. The issue has been patched in version 13.12.2 of the swagger-typescript-api package. Users are strongly advised to update to the fixed version immediately.
Technical details
Mitigation steps:
Affected products:
swagger-typescript-api
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54661
https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de
https://github.com/acacode/swagger-typescript-api/pull/1779
https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2
https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-38c3-wv3c-v3xj
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
