Skip to content
InYourGeek
visiteur@inyourgeek — shell
compléter historique ouvrirhelp
FR
← Back to the register

@typespec/openapi3

HighnpmGHSA-2q42-4q24-7rgv

What to do

No fixed version has been published yet. Versions <= 1.15.0 are affected: apply the workaround described in the advisory.

A path traversal flaw affects the npm package @typespec/openapi3. Affected versions: <= 1.15.0. No fixed version published so far. CVSS score 7.1.

What the flaw allows: Files outside the intended scope can be read or written.

Package
@typespec/openapi3
Ecosystem
npm (JavaScript)
Class
Path traversal
Affected versions
<= 1.15.0
CVSS
7.1
Published on
September 8, 2026

Sources

Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.