THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-h754-fxp7-88wx (high) — swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

[GHSA] GHSA-h754-fxp7-88wx (high) — swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

highgithub_advisoriesPublished 2026-07-29

GHSA-h754-fxp7-88wx Severity: high CVE: CVE-2026-54660

swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`

### Summary

When the developer supplies an `--authorizationToken` (commonly required to fetch a private spec behind authentication), `swagger-typescript-api` attaches that token to the `Authorization` header of **every** subsequent HTTP request it makes wh

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-h754-fxp7-88wx