CVE-2026-54664

Summary

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parsers/enum.ts passes components.schemas.*.enum[i] values to Ts.StringValue in src/configuration.ts without escaping before templates/base/enum-data-contract.ejs renders TypeScript enum declarations, allowing an attacker-controlled OpenAPI spec to inject code that executes when the generated module is imported. This issue is fixed in version 13.12.2.

Affected Software

VendorProductVersion RangeStatus
acacodeswagger-typescript-api< 13.12.2affected

Weaknesses

  • CWE-74: CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
  • CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
  • CWE-1336: CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine

References