Skip to content
Critical Code Injection Vulnerability in openapi-typescript-codegen Disclosed

Critical Code Injection Vulnerability in openapi-typescript-codegen Disclosed

First seen 11 Oct 2026, 16:34 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 17:31 UTC
  • •CVE-2026-108551 has a CVSS score of 9.8, classified as critical.
  • •The vulnerability allows JavaScript injection via unescaped Handlebars interpolation in OpenAPI specs.
  • •No public exploit code exists, and it is not currently listed as actively exploited.

A critical code injection vulnerability, CVE-2026-108551, was disclosed on October 10, 2026, affecting openapi-typescript-codegen versions up to 0.31.0. The flaw allows attackers to inject JavaScript into generated TypeScript clients via unescaped values in OpenAPI documents, potentially compromising CI/CD pipelines. This vulnerability has a CVSS score of 9.8, indicating a high risk of remote code execution without authentication. Currently, there is no public exploit code available, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. Organizations are advised to apply security patches and monitor systems for signs of exploitation. The vulnerability primarily impacts developers and organizations using the affected code generator in their build environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-10
CVE-2026-108551 published
The vulnerability was disclosed, allowing code injection in openapi-typescript-codegen through version 0.31.0.
Thehackerwire
2026-10-10
CVE-2026-108598 published
Another critical vulnerability was disclosed affecting the Floci Velocity template engine, also rated CVSS 9.8.
threataft.com

More articles in this cluster (4)

Following this threat?

Track CVE-2026-108551 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What versions are affected by CVE-2026-108551?
All versions of openapi-typescript-codegen up to and including 0.31.0 are affected.
Is there a patch available for this vulnerability?
A patch is pending for openapi-typescript-codegen beyond version 0.31.0.
How can organizations protect themselves?
Organizations should apply the latest security patches, monitor for exploitation signs, and review their CI/CD pipeline configurations.