CVE-2026-108551 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-108551 requires immediate attention.

· 7 min read

Executive Summary

CVE-2026-108551 is a critical code injection flaw in openapi-typescript-codegen through 0.31.0 (CVSS 9.8). If you generate API clients from OpenAPI documents, this issue can let an attacker who controls the spec inject JavaScript into generated code by placing a single quote in fields such as path keys, parameter names, servers[0].url, or info.version. The dangerous part: the payload can execute when the generated client is imported or when service methods are called.

This is especially urgent for solo developers and small teams because the vulnerable pattern often lives in build pipelines and internal tooling, not just production apps. Even if the CVE is not known to be exploited in the wild and is not in CISA KEV, treat it as an immediate fix.

Immediate Action

  • Stop generating clients from untrusted or externally supplied OpenAPI documents until you have patched or isolated the generator.
  • Upgrade openapi-typescript-codegen immediately to the first fixed release: TODO: insert fixed version or later. If no fixed version is available yet, pin to a safe alternative or disable generation.
  • Rollback any recently generated client code if the OpenAPI source may have been attacker-controlled or modified without review.
  • Isolate the generator in a throwaway container/VM and run it only on trusted specs until remediation is complete.
  • Review vendor notes and release advisories for the package: vendor advisory / release notes.

Affected Versions

  • openapi-typescript-codegen@<=0.31.0 vulnerable
  • openapi-typescript-codegen@TODO_FIXED_VERSION+ safe, if confirmed by release notes
  • If you vendor the generated output, any client generated from a malicious spec may also be unsafe until regenerated from a trusted, patched workflow

Resolution Guide

JavaScript / TypeScript

# npm
npm install openapi-typescript-codegen@TODO_FIXED_VERSION --save-dev

# yarn
yarn add -D openapi-typescript-codegen@TODO_FIXED_VERSION

# pnpm
pnpm add -D openapi-typescript-codegen@TODO_FIXED_VERSION

Python wrappers / automation (if you invoke the generator from scripts or tooling)

# pip
pip install "openapi-typescript-codegen==TODO_FIXED_VERSION"

# pipx
pipx upgrade openapi-typescript-codegen

Java build pipelines (only if the generator is wrapped by a Maven/Gradle task or plugin in your build)

# Maven: pin the wrapper/plugin version in pom.xml to TODO_FIXED_VERSION
# Gradle: pin the task/plugin dependency to TODO_FIXED_VERSION

Linux package managers (if packaged internally or installed via OS tooling)

# apt
sudo apt update && sudo apt install --only-upgrade TODO_PACKAGE_NAME

# yum/dnf
sudo yum update TODO_PACKAGE_NAME
# or
sudo dnf upgrade TODO_PACKAGE_NAME

Docker

# Pull a rebuilt image that includes the fixed generator
docker pull TODO_IMAGE:TODO_FIXED_TAG

# Rebuild your image after updating package lockfiles
docker build --no-cache -t your-app:fixed .

Hardening / containment

# Disable generation from untrusted specs in CI
export DISABLE_OPENAPI_CODEGEN=1

# Example feature flag in app config
OPENAPI_GENERATION_ENABLED=false

Minimal code fix example if you maintain a fork or wrapper: escape single quotes before interpolating into single-quoted JavaScript strings.

function escapeSingleQuotes(value: string): string {
  return value.replace(/\\/g, '\\\\').replace(/'/g, "\\'");
}

// Before:
const line = `const x = '${input}';`;

// After:
const line = `const x = '${escapeSingleQuotes(input)}';`;

Detection & Verification

Check installed versions

npm ls openapi-typescript-codegen
yarn why openapi-typescript-codegen
pnpm why openapi-typescript-codegen

Search lockfiles and build configs

grep -R "openapi-typescript-codegen" package.json package-lock.json yarn.lock pnpm-lock.yaml .

Look for risky generated patterns in generated client output:

grep -R "servers\\[0\\]\\.url\|info\\.version\|parameter\|path" src generated .
grep -R "'" generated/ | head

Dependency audit

npm audit
yarn audit
pnpm audit

Verify the fix

# Confirm the package version is above the vulnerable range
npm ls openapi-typescript-codegen

# Regenerate the client from a trusted spec and ensure no JS executes on import
npm run generate-client
node -e "require('./generated-client')"

If you use CI, add a gate that rejects specs containing unexpected single quotes in fields used by code generation, and require human review for any external OpenAPI source.

Risk and Impact

This vulnerability can turn a malicious OpenAPI document into executable JavaScript inside your build or application runtime. The blast radius includes credential theft, supply-chain compromise, tampering with generated API clients, and arbitrary actions in the context of the developer machine or CI runner.

For small teams, the most likely failure mode is a trusted-looking spec update that silently poisons generated code. If your workflow auto-generates clients, assume the attacker can reach every downstream app that imports that client until you patch and regenerate from a trusted source.

Keep reading