CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54664

highCVSS 8.3covered by 2 sourcesfirst seen 2026-07-29
Summary swagger-typescript-api interpolates components.schemas.*.enum[i] string values into the body of generated TypeScript enum declarations without escaping. A malicious enum value can close the enclosing string literal, terminate the enum body, and inject a bare-block IIFE that executes at module load the first time the generated client is imported. The trigger requires no instantiation and no method call — only an import of the generated module. The attacker controls the OpenAPI spec (remote --url, third-party / public spec, multi-tenant platform); the victim is whoever runs the generator and imports the result (the developer, their CI runner, or any downstream consumer of the generated package). Impact is arbitrary code execution with the importing process's privileges — read any file the importer can read, write any file, exfiltrate secrets, etc. Details The root cause is Ts.StringValue in src/configuration.ts:250: StringValue: (content: unknown) => "${content}", It wraps a value in double quotes with zero escaping — no handling of ", \, newlines, or anything else. The codebase's only escape function (escapeJSDocContent in src/schema-parser/schema-formatters.ts:127) only replaces */ and is never applied to this path. Enum string values reach Ts.StringValue at src/schema-parser/base-schema-parsers/enum.ts:100 and :116: return this.config.Ts.StringValue(value); // ... value: this.config.Ts.StringValue(enumName), The result is interpolated raw into the enum body in templates/base/enum-data-contract.ejs (default enumStyle: "enum" branch, lines 24-31): export enum <%~ name %> { <%~ _.map($content, ({ key, value, description }) => { ... return [ formattedDescription && /** ${formattedDescription} */, ${key} = ${value} ].filter(Boolean).join("\n"); }).join(",\n") %> } Where ${value} is the result of Ts.StringValue — raw "${content}". An attacker-controlled enum value containing a " closes the string and exposes the surrounding code position to injection.

⚡ Watch CVE-2026-54664

Get an email if CVE-2026-54664 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-54664

CVE.org record

Embed the live status

CVE-2026-54664 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54664 status](https://www.csirts.com/badge/CVE-2026-54664)](https://www.csirts.com/cve/CVE-2026-54664)