swagger-typescript-api is vulnerable to Improper Encoding or Escaping of Output
41
Medium Risk
Affected versions of this package allow untrusted OpenAPI fields (e.g., descriptions, examples, patterns) containing */ to prematurely terminate JSDoc comments in generated TypeScript, resulting in malformed code and potential comment injection. An attacker controlling or influencing the OpenAPI specification could craft malicious values that break code generation, inject unintended content into source files, or disrupt build pipelines and downstream tooling. This may enable denial of service in CI/CD processes or facilitate further code manipulation if generated artifacts are trusted or executed without validation.
You are affected if you are using a version that falls within the vulnerable range.
swagger-typescript-api is vulnerable to Improper Encoding or Escaping of Output in versions 11.0.0 - 13.2.17.
Upgrade the swagger-typescript-api library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant