@typespec/openapi3
HighnpmGHSA-2q42-4q24-7rgv
What to do
No fixed version has been published yet. Versions <= 1.15.0 are affected: apply the workaround described in the advisory.
A path traversal flaw affects the npm package @typespec/openapi3. Affected versions: <= 1.15.0. No fixed version published so far. CVSS score 7.1.
What the flaw allows: Files outside the intended scope can be read or written.
- Package
- @typespec/openapi3
- Ecosystem
- npm (JavaScript)
- Class
- Path traversal
- Affected versions
- <= 1.15.0
- CVSS
- 7.1
- Published on
- September 8, 2026
Sources
Entry built automatically from the cited security advisory, with no model rewriting. Acknowledged by the organisation or vendor, notified to an authority, or established by two independent sources.