CVE-2026-108551 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-108551 requires immediate attention.
· 7 min read
Executive Summary
CVE-2026-108551 is a critical code injection flaw in openapi-typescript-codegen through 0.31.0 (CVSS 9.8). If you generate API clients from OpenAPI documents, this issue can let an attacker who controls the spec inject JavaScript into generated code by placing a single quote in fields such as path keys, parameter names, servers[0].url, or info.version. The dangerous part: the payload can execute when the generated client is imported or when service methods are called.
This is especially urgent for solo developers and small teams because the vulnerable pattern often lives in build pipelines and internal tooling, not just production apps. Even if the CVE is not known to be exploited in the wild and is not in CISA KEV, treat it as an immediate fix.
Immediate Action
- Stop generating clients from untrusted or externally supplied OpenAPI documents until you have patched or isolated the generator.
- Upgrade
openapi-typescript-codegenimmediately to the first fixed release:TODO: insert fixed versionor later. If no fixed version is available yet, pin to a safe alternative or disable generation. - Rollback any recently generated client code if the OpenAPI source may have been attacker-controlled or modified without review.
- Isolate the generator in a throwaway container/VM and run it only on trusted specs until remediation is complete.
- Review vendor notes and release advisories for the package: vendor advisory / release notes.
Affected Versions
openapi-typescript-codegen@<=0.31.0vulnerableopenapi-typescript-codegen@TODO_FIXED_VERSION+safe, if confirmed by release notes- If you vendor the generated output, any client generated from a malicious spec may also be unsafe until regenerated from a trusted, patched workflow
Resolution Guide
JavaScript / TypeScript
# npm
npm install openapi-typescript-codegen@TODO_FIXED_VERSION --save-dev
# yarn
yarn add -D openapi-typescript-codegen@TODO_FIXED_VERSION
# pnpm
pnpm add -D openapi-typescript-codegen@TODO_FIXED_VERSION
Python wrappers / automation (if you invoke the generator from scripts or tooling)
# pip
pip install "openapi-typescript-codegen==TODO_FIXED_VERSION"
# pipx
pipx upgrade openapi-typescript-codegen
Java build pipelines (only if the generator is wrapped by a Maven/Gradle task or plugin in your build)
# Maven: pin the wrapper/plugin version in pom.xml to TODO_FIXED_VERSION
# Gradle: pin the task/plugin dependency to TODO_FIXED_VERSION
Linux package managers (if packaged internally or installed via OS tooling)
# apt
sudo apt update && sudo apt install --only-upgrade TODO_PACKAGE_NAME
# yum/dnf
sudo yum update TODO_PACKAGE_NAME
# or
sudo dnf upgrade TODO_PACKAGE_NAME
Docker
# Pull a rebuilt image that includes the fixed generator
docker pull TODO_IMAGE:TODO_FIXED_TAG
# Rebuild your image after updating package lockfiles
docker build --no-cache -t your-app:fixed .
Hardening / containment
# Disable generation from untrusted specs in CI
export DISABLE_OPENAPI_CODEGEN=1
# Example feature flag in app config
OPENAPI_GENERATION_ENABLED=false
Minimal code fix example if you maintain a fork or wrapper: escape single quotes before interpolating into single-quoted JavaScript strings.
function escapeSingleQuotes(value: string): string {
return value.replace(/\\/g, '\\\\').replace(/'/g, "\\'");
}
// Before:
const line = `const x = '${input}';`;
// After:
const line = `const x = '${escapeSingleQuotes(input)}';`;
Detection & Verification
Check installed versions
npm ls openapi-typescript-codegen
yarn why openapi-typescript-codegen
pnpm why openapi-typescript-codegen
Search lockfiles and build configs
grep -R "openapi-typescript-codegen" package.json package-lock.json yarn.lock pnpm-lock.yaml .
Look for risky generated patterns in generated client output:
grep -R "servers\\[0\\]\\.url\|info\\.version\|parameter\|path" src generated .
grep -R "'" generated/ | head
Dependency audit
npm audit
yarn audit
pnpm audit
Verify the fix
# Confirm the package version is above the vulnerable range
npm ls openapi-typescript-codegen
# Regenerate the client from a trusted spec and ensure no JS executes on import
npm run generate-client
node -e "require('./generated-client')"
If you use CI, add a gate that rejects specs containing unexpected single quotes in fields used by code generation, and require human review for any external OpenAPI source.
Risk and Impact
This vulnerability can turn a malicious OpenAPI document into executable JavaScript inside your build or application runtime. The blast radius includes credential theft, supply-chain compromise, tampering with generated API clients, and arbitrary actions in the context of the developer machine or CI runner.
For small teams, the most likely failure mode is a trusted-looking spec update that silently poisons generated code. If your workflow auto-generates clients, assume the attacker can reach every downstream app that imports that client until you patch and regenerate from a trusted source.