PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108551 ferdikoomen CVE debrief

CVE-2026-108551 is a critical vulnerability in openapi-typescript-codegen that allows code injection via unescaped values in OpenAPI documents. Attackers can inject JavaScript by embedding single quotes in specific fields, enabling arbitrary code execution when clients are generated and imported or service methods are called. This vulnerability has significant implications for defenders, who must verify and update openapi-typescript-codegen versions, review OpenAPI documents for suspicious fields, and implement compensating controls to prevent code injection. The scope of affected versions and potential impact require further verification from official sources, and defenders should

Vendor
ferdikoomen
Product
openapi-typescript-codegen
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders responsible for openapi-typescript-codegen deployments, developers using OpenAPI documents, and security teams assessing exposure to code injection attacks should be aware of this vulnerability and take necessary actions to prevent exploitation.

Why it matters

CVE-2026-108551 is a critical vulnerability in openapi-typescript-codegen that allows code injection via unescaped values in OpenAPI documents. Defenders should prioritize verifying and updating openapi-typescript-codegen versions, reviewing OpenAPI documents for suspicious fields, and implementing compensating controls to prevent code injection. The scope of affected versions and potential impact require further verification from official sources.

  • Arbitrary code execution when generated clients are imported or service methods called
  • Potential for attackers to inject malicious JavaScript
  • Need for verification of openapi-typescript-codegen versions and OpenAPI documents
  • Importance of implementing compensating controls to prevent code injection

Technical summary

The openapi-typescript-codegen library through version 0.31.0 is vulnerable to code injection. Attackers can inject JavaScript by supplying unescaped values interpolated into single-quoted string literals in OpenAPI documents. This can be achieved by embedding a single quote in path keys, parameter names, servers[0].url, or info.version. When generated clients are imported or service methods called, the injected JavaScript can be executed.

Defensive priority

Defenders should prioritize verifying and updating openapi-typescript-codegen versions, reviewing OpenAPI documents for suspicious fields, and implementing compensating controls to prevent code injection.

Recommended defensive actions

  • Verify and update openapi-typescript-codegen to the latest version
  • Review OpenAPI documents for suspicious fields and values
  • Implement compensating controls to prevent code injection
  • Monitor for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but the scope of affected versions and potential impact require further verification from official sources. To verify, defenders should review the official advisory, assess their exposure, and confirm whether affected product deployments exist in their managed environments. They should also review OpenAPI documents for suspicious fields and values, and implement compensating controls to prevent code injection. Additionally, defenders should monitor for potential

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108551 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108551

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108551 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108551

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.