What is CVE-2026-54663?
CVE-2026-54663 is a Server-Side Request Forgery (SSRF) vulnerability in swagger-typescript-api when resolving external $ref URLs from OpenAPI specifications in versions prior to 13.12.2. This could allow an attacker to make requests to internal network resources. Immediate update to version 13.12.2 or later is strongly recommended.
Azərbaycanca: CVE-2026-54663, swagger-typescript-api aləti vasitəsilə OpenAPI spesifikasiyasından API müştəriləri yaradan zaman xarici $ref URL-lərini həll edərkən baş verən Server-Side Request Forgery (SSRF) zəifliyidir. Bu, 13.12.2 versiyasından əvvəlki versiyalara təsir edir və təcavüzkara şəbəkə daxilinə sorğu göndərməyə imkan verə bilər. Dərhal 13.12.2 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which tool is affected by CVE-2026-54663?
CVE-2026-54663 affects the swagger-typescript-api tool.
To which version should one update to mitigate CVE-2026-54663?
To protect against this vulnerability, it is recommended to immediately update to version 13.12.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.