swagger-typescript-api has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was July 2026 with 6. The median CVSS is 8.3 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-1336 (4) and CWE-74 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.3
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Weakness classes
Products
- swagger-typescript-api 6
Worst active — by depth score
CVE-2026-54666High· 8.3swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies46CVE-2026-54664High· 8.3swagger-typescript-api vulnerable to code injection via unescaped enum string values46CVE-2026-54662High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template46CVE-2026-54661High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template46CVE-2026-54660High· 7.4swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`41
swagger-typescript-api vulnerabilities
CVEs affecting swagger-typescript-api, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-54660High· 7.4swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`
CVE-2026-54662High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
CVE-2026-54663Medium· 6.1swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`
CVE-2026-54661High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
CVE-2026-54664High· 8.3swagger-typescript-api vulnerable to code injection via unescaped enum string values
swagger-typescript-api vulnerable to code injection via unescaped enum string values
CVE-2026-54666High· 8.3swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies