Security: acacode/swagger-typescript-api
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Server-Side Request Forgery via spec `$ref`; generator makes attacker-directed HTTP requests during code generation when run against an attacker-controlled OpenAPI specGHSA-x36r-4347-pm5x published
Jun 8, 2026 by js2meModerate -
Code injection via unescaped `servers[0].url` in axios http-client template; per-instance RCE on `new HttpClient()` when run against an attacker-controlled OpenAPI specGHSA-38c3-wv3c-v3xj published
Jun 8, 2026 by js2meHigh -
Code injection via unescaped OpenAPI path strings in generated method bodies; per-method-call RCEGHSA-w284-33mx-6g9v published
Jun 8, 2026 by js2meHigh -
Code injection via unescaped enum string values; module-load RCE in generated client when run against an attacker-controlled OpenAPI specGHSA-5f94-x226-ccpm published
Jun 8, 2026 by js2meHigh -
Code injection via unescaped `servers[0].url` in fetch http-client template; module-load RCE when run against an attacker-controlled OpenAPI specGHSA-hqj5-cw9f-rx67 published
Jun 8, 2026 by js2meHigh
Learn more about advisories related to acacode/swagger-typescript-api in the GitHub Advisory Database