Skip to content
Threat Feed
critical advisory

Code Injection in openapi-typescript-codegen via OpenAPI Document Processing

The openapi-typescript-codegen package through version 0.31.0 is vulnerable to code injection when processing malicious OpenAPI documents, allowing attackers to execute arbitrary JavaScript.

CVE search metadata

CVE search record: CVE-2026-108551. Severity: critical. CVSS: 9.8. KEV: no. Product: openapi-typescript-codegen (<= 0.31.0). Brief: Code Injection in openapi-typescript-codegen via OpenAPI Document Processing. Brief link: https://feed.craftedsignal.io/briefs/2026-10-108551/

The openapi-typescript-codegen library (versions up to and including 0.31.0) contains a code injection vulnerability arising from insufficient sanitization of input values within an OpenAPI specification document. When generating TypeScript clients, the tool interpolates fields such as path keys, parameter names, the servers[0].url field, or the info.version string into single-quoted JavaScript string literals without proper escaping.

An attacker who can provide or influence an OpenAPI document processed by this library can inject a single quote character to break out of the intended string literal. This allows for the injection and execution of arbitrary JavaScript code during the client generation phase or when service methods are subsequently invoked in a client application. This vulnerability presents a high risk for CI/CD pipelines and automated workflows that ingest external or untrusted OpenAPI definitions to generate API client code.

Impact

Successful exploitation leads to arbitrary code execution within the context of the environment running the code generation tool or the consumer of the generated client. This could facilitate command execution, data exfiltration, or secondary supply chain attacks if the generated client is integrated into downstream software.

Recommendation

  • Immediately update the openapi-typescript-codegen dependency to a version beyond 0.31.0 that includes sanitization fixes for input interpolation.
  • Audit all build and development pipelines that use this library to ingest OpenAPI definitions from external, third-party, or user-provided sources.
  • Implement strict input validation for any OpenAPI documents that are automatically processed by internal CI/CD tooling.

Immediate actions

Upgrade openapi-typescript-codegen to a patched version.

IT Operations 24h

Mitigations

Upgrade openapi-typescript-codegen beyond 0.31.0

immediate IT Operations

CVE-2026-108551