THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hqj5-cw9f-rx67 (high) — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

[GHSA] GHSA-hqj5-cw9f-rx67 (high) — swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

highgithub_advisoriesPublished 2026-07-29

GHSA-hqj5-cw9f-rx67 Severity: high CVE: CVE-2026-54662

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

### Summary

`swagger-typescript-api` interpolates `servers[0].url` directly into a TypeScript class-body field initializer of the generated **fetch** `HttpClient` (`templates/base/http-clients/fetch-http-client.ejs:75`), without

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hqj5-cw9f-rx67