THREAT OPS › Threat News › [GHSA] GHSA-2q42-4q24-7rgv (high) — OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
[GHSA] GHSA-2q42-4q24-7rgv (high) — OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
GHSA-2q42-4q24-7rgv Severity: high CVE: None
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
### Summary
The `@typespec/openapi3` emitter retains the value of a `@versioned` enum member and interpolates it into the output filename as `{version}` without sanitizing path separators or traversal components. The completed path reaches the compiler'
MITRE ATT&CK techniques
Indicators of compromise
- 02dc7d056c2f773e56e2c1849947888b039f127ddd630c0bd76a5d7a9ca29cbdsha256
- 7a8067bc04e42a025de90fd7aff9be4df59f005d192f2116eecfb107d7bffd78sha256
- 2992b399c1573c9bd2130794f8554c4026bf425861f74e78b5d89ae0324b5e38sha256
- f30cd352f93997e04c75d48c7ace6947a1d5d07asha1
- 365ec52b50b82cd9e1e037de4c6fcd5de7e32e90sha1
Original source: https://github.com/advisories/GHSA-2q42-4q24-7rgv