{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openapi-typescript-codegen--0.31.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openapi-typescript-codegen_project:openapi-typescript-codegen:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-108551"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["openapi-typescript-codegen (\u003c= 0.31.0)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe openapi-typescript-codegen library (versions up to and including 0.31.0) contains a code injection vulnerability arising from insufficient sanitization of input values within an OpenAPI specification document. When generating TypeScript clients, the tool interpolates fields such as path keys, parameter names, the \u003ccode\u003eservers[0].url\u003c/code\u003e field, or the \u003ccode\u003einfo.version\u003c/code\u003e string into single-quoted JavaScript string literals without proper escaping.\u003c/p\u003e\n\u003cp\u003eAn attacker who can provide or influence an OpenAPI document processed by this library can inject a single quote character to break out of the intended string literal. This allows for the injection and execution of arbitrary JavaScript code during the client generation phase or when service methods are subsequently invoked in a client application. This vulnerability presents a high risk for CI/CD pipelines and automated workflows that ingest external or untrusted OpenAPI definitions to generate API client code.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to arbitrary code execution within the context of the environment running the code generation tool or the consumer of the generated client. This could facilitate command execution, data exfiltration, or secondary supply chain attacks if the generated client is integrated into downstream software.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the \u003ccode\u003eopenapi-typescript-codegen\u003c/code\u003e dependency to a version beyond 0.31.0 that includes sanitization fixes for input interpolation.\u003c/li\u003e\n\u003cli\u003eAudit all build and development pipelines that use this library to ingest OpenAPI definitions from external, third-party, or user-provided sources.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation for any OpenAPI documents that are automatically processed by internal CI/CD tooling.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T17:55:11Z","date_published":"2026-10-10T17:55:11Z","id":"https://feed.craftedsignal.io/briefs/2026-10-108551/","summary":"The openapi-typescript-codegen package through version 0.31.0 is vulnerable to code injection when processing malicious OpenAPI documents, allowing attackers to execute arbitrary JavaScript.","title":"Code Injection in openapi-typescript-codegen via OpenAPI Document Processing","url":"https://feed.craftedsignal.io/briefs/2026-10-108551/"}],"language":"en","title":"CraftedSignal Threat Feed - Openapi-Typescript-Codegen (\u003c= 0.31.0)","version":"https://jsonfeed.org/version/1.1"}