


Perceptive Security
SOC/SIEM Consultancy

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemoteRequestHe…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 16:02:53
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies, Identity & Access, Data Breach & Exfiltration
CVE-2026-54660 affects swagger-typescript-api, a tool that generates API clients for Fetch or Axios from OpenAPI specifications. Prior to version 13.12.2, the function getRemoteRequestHeaders in src/resolved-swagger-schema.ts forwards the --authorizationToken to every URL fetched by fetchRemoteSchemaDocument. When warmUpRemoteSchemasCache resolves external $ref URLs, an attacker-controlled OpenAPI specification can exploit this behavior to exfiltrate developer or CI/CD pipeline bearer tokens to a cross-origin endpoint. This represents a supply chain risk as developers or automated CI systems processing malicious OpenAPI specs could have their credentials stolen. The vulnerability is fixed in version 13.12.2 of swagger-typescript-api. Users are advised to upgrade immediately to mitigate the risk of token exfiltration.
Technical details
Mitigation steps:
Affected products:
swagger-typescript-api
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54660
https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de
https://github.com/acacode/swagger-typescript-api/pull/1779
https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2
https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-h754-fxp7-88wx
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
