THREAT OPS › Threat News › [GHSA] GHSA-hqj5-cw9f-rx67 (high) — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
[GHSA] GHSA-hqj5-cw9f-rx67 (high) — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
GHSA-hqj5-cw9f-rx67 Severity: high CVE: CVE-2026-54662
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
### Summary
`swagger-typescript-api` interpolates `servers[0].url` directly into a TypeScript class-body field initializer of the generated **fetch** `HttpClient` (`templates/base/http-clients/fetch-http-client.ejs:75`), without
Indicators of compromise
- CVE-2026-54662cve
- https://api.example.com\url
- https://attacker.example/openapi.json`url
Original source: https://github.com/advisories/GHSA-hqj5-cw9f-rx67