top of page
perceptive_background_267k.jpg

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHe…

Published:

28 juli 2026 om 22:00:00

Alert date:

29 juli 2026 om 16:02:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies, Identity & Access, Data Breach & Exfiltration

CVE-2026-54660 affects swagger-typescript-api, a tool that generates API clients for Fetch or Axios from OpenAPI specifications. Prior to version 13.12.2, the function getRemoteRequestHeaders in src/resolved-swagger-schema.ts forwards the --authorizationToken to every URL fetched by fetchRemoteSchemaDocument. When warmUpRemoteSchemasCache resolves external $ref URLs, an attacker-controlled OpenAPI specification can exploit this behavior to exfiltrate developer or CI/CD pipeline bearer tokens to a cross-origin endpoint. This represents a supply chain risk as developers or automated CI systems processing malicious OpenAPI specs could have their credentials stolen. The vulnerability is fixed in version 13.12.2 of swagger-typescript-api. Users are advised to upgrade immediately to mitigate the risk of token exfiltration.

Technical details

Mitigation steps:

Affected products:

swagger-typescript-api

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page