


Perceptive Security
SOC/SIEM Consultancy

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts p…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 16:02:53
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
A code injection vulnerability exists in swagger-typescript-api prior to version 13.12.2. The flaw resides in how enum values from OpenAPI specification components are passed to the TypeScript string value handler without proper escaping before being rendered into TypeScript enum declarations via an EJS template. An attacker who controls an OpenAPI specification file can inject arbitrary code that executes when the generated TypeScript module is imported. The vulnerability affects the src/schema-parser/base-schema-parsers/enum.ts and src/configuration.ts files. The issue has been assigned CVE-2026-54664 and is fixed in version 13.12.2. Users are advised to upgrade immediately to the patched version to mitigate the risk of supply chain code injection attacks.
Technical details
Mitigation steps:
Affected products:
swagger-typescript-api
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54664
https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de
https://github.com/acacode/swagger-typescript-api/pull/1779
https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2
https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-5f94-x226-ccpm
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
