Executive brief
swagger-typescript-api is a code generator that creates TypeScript API clients from OpenAPI specifications. A vulnerability in its axios client template allows attackers who control the OpenAPI spec to inject arbitrary code that executes when the generated client is instantiated. This leads to remote code execution with the privileges of the importing application, potentially allowing data exfiltration, malware installation, or system compromise.
Technical details
The vulnerability is a template-engine injection (CWE-1336) in the axios http-client code generation path. The root cause is in templates/base/http-clients/axios-http-client.ejs:71, which uses raw (unescaped) Eta interpolation (<%~ %>) to insert apiConfig.baseUrl into a JavaScript object literal argument to axios.create({...}) inside the HttpClient constructor body. An attacker-controlled servers[0].url value like `"URL", [(IIFE)()]: 0, dummy: "` closes the baseURL string literal and injects a computed property key containing an IIFE that executes eagerly when the object is constructed—that is, every time new HttpClient() runs. The trailing dummy property reopens a string to maintain syntactic validity. Attack surface includes any developer or pipeline running swagger-typescript-api with --http-client axios against third-party, vendor, or attacker-hosted OpenAPI specs. The documented usage pattern of `const api = new Api()` at module top level means the payload fires at module import time. Patches applied in PR #1779 escape apiConfig.baseUrl and other untrusted spec fields before templating, block SSRF in remote $ref resolution, and validate redirect targets.
Affected products
- acacode swagger-typescript-api <= 13.12.1
Timeline
- 2026-07-29: disclosed
- 2026-06-08: patched: Security fix merged in PR #1779 (commit 306d59ac)
References
- https://github.com/acacode/swagger-typescript-api/security/advisories/GHSA-38c3-wv3c-v3xj
- https://github.com/acacode/swagger-typescript-api/pull/1779
- https://github.com/acacode/swagger-typescript-api/commit/306d59acb8ffbb00f953f807b97234b21f51d9de
- https://github.com/acacode/swagger-typescript-api
- https://github.com/acacode/swagger-typescript-api/releases/tag/v13.12.2