top of page
perceptive_background_267k.jpg

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts p…

Published:

28 juli 2026 om 22:00:00

Alert date:

29 juli 2026 om 16:02:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

A code injection vulnerability exists in swagger-typescript-api prior to version 13.12.2. The flaw resides in how enum values from OpenAPI specification components are passed to the TypeScript string value handler without proper escaping before being rendered into TypeScript enum declarations via an EJS template. An attacker who controls an OpenAPI specification file can inject arbitrary code that executes when the generated TypeScript module is imported. The vulnerability affects the src/schema-parser/base-schema-parsers/enum.ts and src/configuration.ts files. The issue has been assigned CVE-2026-54664 and is fixed in version 13.12.2. Users are advised to upgrade immediately to the patched version to mitigate the risk of supply chain code injection attacks.

Technical details

Mitigation steps:

Affected products:

swagger-typescript-api

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page