THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-38c3-wv3c-v3xj (high) — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

[GHSA] GHSA-38c3-wv3c-v3xj (high) — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

highgithub_advisoriesPublished 2026-07-29

GHSA-38c3-wv3c-v3xj Severity: high CVE: CVE-2026-54661

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

### Summary

`swagger-typescript-api` interpolates `servers[0].url` directly into a TypeScript string literal inside the `HttpClient` constructor body of the generated **axios** client (`templates/base/http-clients/axios-http-clie

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-38c3-wv3c-v3xj