HIGH8.3npm
GHSA-38c3-wv3c-v3xj· CVE-2026-54661swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
Modified: 7/29/2026
package
pkg:npm/swagger-typescript-api
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
Modified: 7/29/2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
Modified: 7/29/2026
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
Modified: 7/29/2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
Modified: 8/13/2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
Modified: 7/29/2026
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
Modified: 7/29/2026