THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w284-33mx-6g9v (high) — swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

[GHSA] GHSA-w284-33mx-6g9v (high) — swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

highgithub_advisoriesPublished 2026-07-29

GHSA-w284-33mx-6g9v Severity: high CVE: CVE-2026-54666

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

### Summary

`swagger-typescript-api` interpolates OpenAPI path strings (the keys of the `paths` object, e.g. `/users/{id}`) directly into a JavaScript template literal inside the body of every generated API method, without escap

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w284-33mx-6g9v