THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2q42-4q24-7rgv (high) — OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

[GHSA] GHSA-2q42-4q24-7rgv (high) — OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

highgithub_advisoriesPublished 2026-09-08

GHSA-2q42-4q24-7rgv Severity: high CVE: None

OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

### Summary

The `@typespec/openapi3` emitter retains the value of a `@versioned` enum member and interpolates it into the output filename as `{version}` without sanitizing path separators or traversal components. The completed path reaches the compiler'

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-2q42-4q24-7rgv