threataft.com Critical Code Injection Vulnerability in openapi-typescript-codegen Disclosed
Article Content
- •CVE-2026-108551 has a CVSS score of 9.8, classified as critical.
- •The vulnerability allows JavaScript injection via unescaped Handlebars interpolation in OpenAPI specs.
- •No public exploit code exists, and it is not currently listed as actively exploited.
A critical code injection vulnerability, CVE-2026-108551, was disclosed on October 10, 2026, affecting openapi-typescript-codegen versions up to 0.31.0. The flaw allows attackers to inject JavaScript into generated TypeScript clients via unescaped values in OpenAPI documents, potentially compromising CI/CD pipelines. This vulnerability has a CVSS score of 9.8, indicating a high risk of remote code execution without authentication. Currently, there is no public exploit code available, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. Organizations are advised to apply security patches and monitor systems for signs of exploitation. The vulnerability primarily impacts developers and organizations using the affected code generator in their build environments.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2026-108551 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What versions are affected by CVE-2026-108551?
Is there a patch available for this vulnerability?
How can organizations protect themselves?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…