CRITICAL
ferdikoomen
CVE published 2026-10-10
CVE-2026-108551
CVE-2026-108551 is a critical vulnerability in openapi-typescript-codegen that allows code injection via unescaped values in OpenAPI documents. Attackers can inject JavaScript by embedding single quotes in specific fields, enabling arbitrary code execution when clients are generated and imported or service methods are called. This vulnerability has significant implications for defenders, who must verify a [truncated]