Advisory · CVE-2026-108551
openapi-typescript-codegen lets a malicious OpenAPI spec inject JavaScript into generated clients
Versions through 0.31.0 interpolate spec-controlled values into single-quoted string literals without escaping; a crafted spec can execute arbitrary JavaScript when a generated client is imported or a service method is called.
- Vendor
- ferdikoomen
- Product
- openapi-typescript-codegen
- Identifier / CWE
- CVE-2026-108551
CWE-94 - Action timing
- Immediate
Explain it like I’m five
The generator copies words from an API description straight into the code it writes, inside quote marks. If someone hides a quote mark plus instructions in the description, the quote closes early and the instructions become live code that runs whenever the generated client loads.
- 01Attacker crafts spec
An attacker embeds a single quote plus JavaScript in a path key, parameter name, the first server URL, or the API version of an OpenAPI document.
- 02Victim generates client
A developer or CI pipeline runs openapi-typescript-codegen against the untrusted spec. Templates emit the raw values into single-quoted string literals with no escaping.
- 03Payload becomes live code
The injected quote closes the string early, so the rest is emitted as executable JavaScript in the generated output, including core/OpenAPI.ts which every service file imports.
- 04Code executes
Importing the client runs the payload immediately (server URL or version field), or calling the affected method runs it on each call (path or parameter name).
What happened
Versions of openapi-typescript-codegen through 0.31.0 interpolate values taken directly from an OpenAPI document into single-quoted JavaScript string literals in generated output, with no escaping. Several fields are affected: the request path, each parameter’s wire name, the request-body media type, response header names, the first server URL, and the API version.
A single quote in any of these values closes the string literal early, and everything after it is evaluated as live JavaScript. The issue report confirms this on the current main branch and across all generated HTTP clients (fetch, axios, xhr, node, angular).
The impact splits in two. Injecting through the server URL or API version gives import-time code execution: core/OpenAPI.ts, imported by every generated service file, runs the payload as soon as it is loaded. Injecting through a request path or parameter name gives per-call execution: the payload runs each time the affected generated method is invoked. Any workflow that generates or runs a client from an attacker-controlled or attacker-influenced spec is exposed, including developers running the generator locally and CI pipelines that regenerate clients from remote specs.
What to do
- Find every project that depends on openapi-typescript-codegen, including lockfiles and CI pipelines that regenerate clients from remote or third-party specs.
- Check the project releases for a patched version newer than 0.31.0 and upgrade; the reporter has a fix prepared, so watch the repository for the release.
- Until you can upgrade, do not generate clients from untrusted or unreviewed OpenAPI documents.
- Audit generated client code for injected JavaScript, especially single-quoted literals in
core/OpenAPI.tsand generated service files built from specs you did not author. - If a pipeline consumed a suspicious spec, treat the build environment as exposed and rotate credentials reachable from it.
Management note
This is a supply-chain-style flaw in developer tooling: the attack enters through an API description, not through the application under development. The two failure modes that matter are CI pipelines that pull specs from third parties and teams that generate clients once and commit the output. Patching plus a policy of never generating from unverified specs closes both.