<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:openapi-Typescript-Codegen_project:openapi-Typescript-Codegen:*:*:*:*:*:node.js:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aopenapi-typescript-codegen_projectopenapi-typescript-codegennode.js/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 17:55:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aopenapi-typescript-codegen_projectopenapi-typescript-codegennode.js/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Code Injection in openapi-typescript-codegen via OpenAPI Document Processing</title><link>https://feed.craftedsignal.io/briefs/2026-10-108551/</link><pubDate>Sat, 10 Oct 2026 17:55:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-108551/</guid><description>The openapi-typescript-codegen package through version 0.31.0 is vulnerable to code injection when processing malicious OpenAPI documents, allowing attackers to execute arbitrary JavaScript.</description><content:encoded><![CDATA[<p>The openapi-typescript-codegen library (versions up to and including 0.31.0) contains a code injection vulnerability arising from insufficient sanitization of input values within an OpenAPI specification document. When generating TypeScript clients, the tool interpolates fields such as path keys, parameter names, the <code>servers[0].url</code> field, or the <code>info.version</code> string into single-quoted JavaScript string literals without proper escaping.</p>
<p>An attacker who can provide or influence an OpenAPI document processed by this library can inject a single quote character to break out of the intended string literal. This allows for the injection and execution of arbitrary JavaScript code during the client generation phase or when service methods are subsequently invoked in a client application. This vulnerability presents a high risk for CI/CD pipelines and automated workflows that ingest external or untrusted OpenAPI definitions to generate API client code.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation leads to arbitrary code execution within the context of the environment running the code generation tool or the consumer of the generated client. This could facilitate command execution, data exfiltration, or secondary supply chain attacks if the generated client is integrated into downstream software.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately update the <code>openapi-typescript-codegen</code> dependency to a version beyond 0.31.0 that includes sanitization fixes for input interpolation.</li>
<li>Audit all build and development pipelines that use this library to ingest OpenAPI definitions from external, third-party, or user-provided sources.</li>
<li>Implement strict input validation for any OpenAPI documents that are automatically processed by internal CI/CD tooling.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>