Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-108551: openapi-typescript-codegen may execute injected JavaScript

CVE-2026-108551 · published today
Summary

The openapi-typescript-codegen tool (up to version 0.31.0) can run malicious code if an attacker supplies a crafted OpenAPI file. By inserting a single quote into certain fields, the generated TypeScript client can execute any JavaScript when it is used. Update to a newer version or restrict the OpenAPI files to trusted sources to prevent this risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ferdikoomen openapi-typescript-codegen <= 0.31.0
Original advisory text
openapi-typescript-codegen through 0.31.0 Code Injection via Handlebars Templates
openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are imported or service methods called.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically (estimated)
  • Gives an attacker full control (estimated)
Severity
9.3 Critical
Type
CWE-94Code Injection
Timeline
Published10 Oct 2026
Updated10 Oct 2026
First seen10 Oct 2026
Sources
CVE-2026-108551 · MITRE
Track software like this
Free during beta