What is CVE-2026-54661?
CVE-2026-54661 is a vulnerability in swagger-typescript-api where the server URL from an OpenAPI specification is interpolated into the HttpClient constructor without escaping. This allows an attacker to perform code injection via a malicious server URL. Users should upgrade to version 13.12.2.
Azərbaycanca: CVE-2026-54661, swagger-typescript-api alətində aşkarlanan zəiflikdir. Bu, OpenAPI spesifikasiyasından əldə edilən server URL-ni HttpClient konstruktoruna qaçış olmadan daxil etdiyinə görə, təcavüzkara kod inyeksiyası (code injection) imkanı verir. İstifadəçilər 13.12.2 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which product is affected by CVE-2026-54661?
This vulnerability affects the swagger-typescript-api tool.
What should users do to remediate CVE-2026-54661?
Users should upgrade to version 13.12.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.