Code injection in openapi-typescript-codegen via untrusted OpenAPI spec
openapi-typescript-codegen through 0.31.0 allows attackers who control an OpenAPI document to inject arbitrary JavaScript into generated clients by supplying unescaped values in interpolated template fields. CVSS 9.8 critical.
- Vendor
- ferdikoomen
- Product
- openapi-typescript-codegen (through 0.31.0)
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- unpatched
- Published
openapi-typescript-codegen through version 0.31.0 does not escape user-controlled string values before interpolating them into generated TypeScript client code. An attacker with write access to an OpenAPI spec consumed by this tool can inject arbitrary JavaScript that ends up verbatim in the generated output.
Affected teams: any CI pipeline or build process that runs openapi-typescript-codegen against a spec from an untrusted or partially-trusted source (fetched URL, third-party registry, shared Swagger Hub entry).
Check the project repository for patch availability. If no updated release is available, verify the integrity of all OpenAPI specs consumed at build time, or evaluate migration to an actively maintained fork.
