THREAT OPS › Threat News › [GHSA] GHSA-38c3-wv3c-v3xj (high) — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
[GHSA] GHSA-38c3-wv3c-v3xj (high) — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
GHSA-38c3-wv3c-v3xj Severity: high CVE: CVE-2026-54661
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
### Summary
`swagger-typescript-api` interpolates `servers[0].url` directly into a TypeScript string literal inside the `HttpClient` constructor body of the generated **axios** client (`templates/base/http-clients/axios-http-clie
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-54661cve
- https://api.example.com\url
- https://attacker.example/openapi.json`url
Original source: https://github.com/advisories/GHSA-38c3-wv3c-v3xj