External risk intelligence

openapi-typescript-codegen Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-108551

This vulnerability exists in a build-time developer tool used to generate code from OpenAPI specifications. It is not a runtime service, web application, or internet-facing appliance. The vulnerable code is executed during the software development lifecycle, not in a deployed production network environment, making public internet exposure of the vulnerable surface very unlikely.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A code injection vulnerability has been identified in a tool used for generating code from OpenAPI specifications. This issue could allow malicious code to be executed if an attacker can control the OpenAPI document used by the tool. The main concern at this time is to confirm if our development processes utilize this specific tool and version, and if so, to understand the potential exposure.

  • Code can be injected through OpenAPI documents.
  • Developers might be at risk if using this tool.
  • Confirm tool usage and assess development environment risk.

Attack Path

How an attacker could exploit the issue

An attacker can inject malicious JavaScript by controlling an OpenAPI document. This document is processed by a code generation tool. The injected code is then embedded into the generated client code. When this client code is imported or used, the embedded JavaScript can be executed.

  • Entry condition: Attacker controls OpenAPI document.
  • Trigger point: Importing generated client code.
  • Resulting risk: Arbitrary JavaScript execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, attackers controlling an OpenAPI document could inject JavaScript into generated clients by supplying unescaped values in specific fields. This could lead to arbitrary JavaScript execution when these clients are imported or their methods are called.

  • Generated client code.
  • Unescaped values in OpenAPI documents.
  • Arbitrary JavaScript execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in a code generation tool requires an assessment by the development or platform engineering teams responsible for the build pipeline. The immediate first step is to identify all instances where this tool is used in the development lifecycle. Subsequently, confirm if the generated code is deployed in a business-critical environment and determine the accountable owner for the affected applications or services.

  • Identify where the tool is used.
  • Verify exposure and criticality of generated code.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is openapi-typescript-codegen?

openapi-typescript-codegen is a developer tool used to automate the creation of client-side code based on OpenAPI specification files. Developers integrate this utility into their build pipelines to transform API definitions into ready-to-use service methods and data models. It simplifies the process of interacting with APIs by ensuring the generated code matches the specification, effectively bridging the gap between API documentation and functional application code.

What does code injection mean for CVE-2026-108551?

This vulnerability is classified as Improper Control of Generation of Code (CWE-94). It occurs when the tool fails to properly sanitize input from an OpenAPI document, allowing malicious text to be interpreted as executable code. In this specific case, the tool embeds provided data into string literals within the output; if an attacker controls that input, they can 'break out' of the intended string and force the generated client to execute arbitrary JavaScript commands.

How is this vulnerability triggered?

The trigger occurs when the tool processes a malicious OpenAPI document containing specially crafted, unescaped single quotes. The code injection happens during the generation phase when the tool writes these malicious values into the resulting client files. Simply having a malicious document does not trigger the bug; the vulnerability manifests only when a developer executes the tool to generate code, and the payload is subsequently triggered when that generated code is imported or called.

Is my application at risk from internet-based attacks?

According to Halo Surface Signal, this risk is very unlikely to manifest as a direct internet-facing attack. Since the vulnerable component functions as a build-time developer tool rather than an active web server or network appliance, it does not typically reside in a production environment. The risk is localized to the software development lifecycle, where the security of the build pipeline and the origin of OpenAPI documents determine the potential impact.

How should I respond to CVE-2026-108551?

The first step is for your development or platform engineering teams to audit the build pipeline to locate where this specific tool is utilized. You must verify if you are using affected versions and determine if the generated output is used in sensitive or business-critical applications. Once usage is confirmed, prioritize assessing the trustworthiness of the OpenAPI sources processed by your build system to ensure they are not controlled by unauthorized parties.

References