top of page
perceptive_background_267k.jpg

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-http-client.e…

Published:

28 July 2026 at 22:00:00

Alert date:

29 July 2026 at 16:02:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

A code injection vulnerability exists in swagger-typescript-api prior to version 13.12.2. The vulnerability resides in the axios-http-client.ejs template, which interpolates the servers[0].url value from an OpenAPI specification into the HttpClient constructor without proper escaping. An attacker who controls the OpenAPI spec can inject arbitrary code that executes when new HttpClient() or new Api() is instantiated. This represents a supply chain risk as developers consuming malicious or attacker-modified OpenAPI specs could have malicious code executed during API client generation. The issue has been patched in version 13.12.2 of the swagger-typescript-api package. Users are strongly advised to update to the fixed version immediately.

Technical details

Mitigation steps:

Affected products:

swagger-typescript-api

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page