Sceawere

Vulnerability Detail

CVE-2026-108551UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Code Injection in openapi-typescript-codegen

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
ferdikoomen
Product
openapi-typescript-codegen
Attack Type
Improper Control of Generation of Code ('Code Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

openapi-typescript-codegen through 0.31.0 contains a code injection vulnerability that allows attackers controlling an OpenAPI document to inject JavaScript by supplying unescaped values interpolated into single-quoted string literals. Attackers can embed a single quote in path keys, parameter names, servers[0].url, or info.version to execute arbitrary JavaScript when generated clients are imported or service methods called.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-10-10T15:16:58.273Z",
  "pubdate": "2026-10-10T15:16:58.273Z",
  "executiveSummary": "The openapi-typescript-codegen library, through version 0.31.0, is susceptible to a code injection vulnerability arising from improper neutralization of input data within OpenAPI specification files.\nThe vulnerability allows an attacker who controls the OpenAPI document to inject arbitrary JavaScript code into the generated client code.\nThis is achieved by manipulating fields such as path keys, parameter names, server URLs, or version strings to include unescaped single quotes.\nWhen a developer imports the generated client or invokes the associated service methods, the injected malicious payload is executed within the execution context of the application.\nThe primary risk is unauthorized code execution, which can lead to data exfiltration, account takeover, or the compromise of the development and production environments utilizing the generated artifacts.\nExploitation does not require prior authentication or complex network exposure; rather, it hinges on the attacker's ability to supply or modify an OpenAPI document that is subsequently processed by the vulnerable tool.\nThis vulnerability effectively turns the code generation pipeline into an attack vector.",
  "technicalDetails": "The root cause of this vulnerability is a failure in the templating engine or string interpolation logic within openapi-typescript-codegen. When generating TypeScript or JavaScript client code, the library interpolates values from the OpenAPI specification into single-quoted string literals without performing adequate character escaping or sanitization.\nSpecifically, the library assumes that values extracted from the JSON or YAML OpenAPI definition are safe for direct inclusion in the output code. An attacker can break out of the intended single-quoted string context by injecting a single quote (') character. By following this quote with standard JavaScript syntax, the attacker can append arbitrary logic that will be interpreted as part of the generated module.\nAffected fields include 'path' keys, 'parameter' names, 'servers[0].url', and 'info.version'. Because these fields are often populated or concatenated dynamically in the generated source code, the injection surface is broad.\nThe attack flow follows these steps: 1) The attacker provides or influences an OpenAPI specification (e.g., via a CI/CD integration, a shared repository, or a malicious API definition file). 2) The user runs openapi-typescript-codegen against this malicious document. 3) The tool parses the document and injects the attacker-supplied, unescaped string into the generated source files. 4) The generated files are saved to the project filesystem. 5) When the project is built or executed, the Node.js runtime or the browser executes the injected JavaScript during the initialization of the generated client module.\nThis vulnerability allows for arbitrary command execution within the context of the machine or browser running the code. In a CI/CD environment, this could allow an attacker to gain persistent access to build servers or steal environment variables (like API keys or cloud credentials) by executing malicious calls back to a controlled server during the generation or runtime phase. The scope of impact is restricted only by the permissions of the process executing the generated client code, potentially resulting in full system compromise if the client is part of a server-side application."
}
CVE-2026-108551: Code Injection in openapi-typescript-codegen (CRITICAL Severity, CVSS: 9.8) | Sceawere