Vulnerability Description
swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and templates/base/http-clients/fetch-http-client.ejs interpolates apiConfig.baseUrl into the generated HttpClient baseUrl field without escaping, allowing an attacker-controlled OpenAPI spec to inject TypeScript static field code that executes when the generated fetch client module is imported. This issue is fixed in version 13.12.2.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f80
- https://github.com/acacode/swagger-typescript-api/pull/1779
- https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2
- https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-hqj5-
- https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-hqj5-
FAQ
What is CVE-2026-54662?
CVE-2026-54662 is a vulnerability with a CVSS score of 8.3 (HIGH). swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfig copies servers[0].url into apiConfig.baseUrl, and...
How severe is CVE-2026-54662?
CVE-2026-54662 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-54662?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.