Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
📦
📦 npm
Not in CISA KEV
HIGH severity

GHSA-2q42-4q24-7rgv

HIGHFix: microsoft/typespec#11777

GHSA-2q42-4q24-7rgv is a high-severity (CVSS 7.1) remote code execution vulnerability in @typespec/openapi3. O3 Security confirms whether GHSA-2q42-4q24-7rgv is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.

OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

Published
Sep 8, 2026
Updated
Sep 8, 2026
Affected
2 pkgs
Patched
None yet
Exploits
None indexed
Exploitation data as of Sep 8, 2026 · OSV.dev, FIRST.org (EPSS)

Real-World Exposure

2 pkgs affected

How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.

12other npm packages depend on this — each one inherits the vulnerability until it's patched upstream
@typespec/openapi3npm
213Kdownloads / week
@typespec/compilernpm
195Kdownloads / week

Description

Summary

The @typespec/openapi3 emitter retains the value of a @versioned enum member and interpolates it into the output filename as {version} without sanitizing path separators or traversal components. The completed path reaches the compiler's emitFile(), which creates the parent directory and writes the file without verifying containment under emitterOutputDir.

A crafted declarative .tsp input can therefore create or overwrite an OpenAPI-formatted .yaml or .json file outside the configured output tree, subject to the compiler process's filesystem permissions. No executable TypeSpec extension or attacker-controlled JavaScript is required.

Affected version

Confirmed on:

  • @typespec/compiler 1.15.0
  • @typespec/openapi3 1.15.0
  • @typespec/http 1.15.0
  • @typespec/versioning 0.85.0
  • release tag commit f30cd352f93997e04c75d48c7ace6947a1d5d07a

The critical openapi.ts and emitter-utils.ts blobs are unchanged on main commit 365ec52b50b82cd9e1e037de4c6fcd5de7e32e90 as checked on 2026-08-19. No patched version was identified.

Root cause

The value originates at packages/openapi3/src/openapi.ts:592-608:

serviceRecord.versions.push({
  service,
  version: snapshot.version!.value,
  document: document[0],
  diagnostics: document[1],
});

It is interpolated without path validation at openapi.ts:629-641:

return interpolatePath(options.outputFile, {
  "openapi-version": specVersion,
  "service-name-if-multiple": multipleService ? getNamespaceFullName(service.type) : undefined,
  "service-name": getNamespaceFullName(service.type),
  "file-type": fileType,
  version,
});

The path reaches emitFile() at openapi.ts:392-401. The sink at packages/compiler/src/core/emitter-utils.ts:29-39 performs no output-root containment check:

const outputFolder = getDirectoryPath(options.path);
await program.host.mkdirp(outputFolder);
return await program.host.writeFile(options.path, content);

resolvePath() joins the template to emitterOutputDir before {version} is interpolated, so it does not see the attacker-controlled .. components.

Proof of concept

The relevant input in poc/main.tsp is:

@versioned(Versions) namespace Svc;
enum Versions { v1: "../../../../../../../../../../tmp/TYPESPEC_PWNED/pwn" }

Run from PowerShell:

cd poc
.\run-revalidation.ps1

The supplied Docker runner uses a digest-pinned Node base, a committed npm integrity lock, disabled runtime networking, a benign control, a 90-second timeout, and cleanup enforcement.

Observed in the preserved identity-locked replay (1/1 attack and 1/1 negative control):

negative_before=02dc7d056c2f773e56e2c1849947888b039f127ddd630c0bd76a5d7a9ca29cbd
negative_after=02dc7d056c2f773e56e2c1849947888b039f127ddd630c0bd76a5d7a9ca29cbd
attack_before=7a8067bc04e42a025de90fd7aff9be4df59f005d192f2116eecfb107d7bffd78
attack_after=2992b399c1573c9bd2130794f8554c4026bf425861f74e78b5d89ae0324b5e38
outside_file_head=openapi: 3.0.0
inside_attack_files=

The benign version preserved the outside canary. The crafted version replaced it with emitted OpenAPI content, and no attack output file remained under tsp-output.

Impact and constraints

Proven impact is out-of-directory YAML/JSON creation or overwrite. The attacker can influence the traversal, final basename, and many strings in the OpenAPI-structured content. The extension is constrained to the selected emitter format, content is not arbitrary bytes, and the target must be writable.

This report demonstrates file corruption. Denial of service is a potential impact when a writable critical file is targeted. It does not claim file disclosure, arbitrary-byte write, deployment takeover, or code execution by a downstream consumer.

Suggested remediation

After every filename token has been interpolated, resolve the completed destination against emitterOutputDir and reject any non-descendant using path-component-aware comparison. Reject or slugify absolute paths, path separators, and traversal components in spec-derived filename tokens. Add regression cases for POSIX and Windows separators, absolute values, sibling-prefix paths, and benign semantic versions.

Affected Packages

2 total
EcosystemPackageVulnerable rangeFix
📦npm@typespec/openapi3all versionsNo fix
📦npm@typespec/compilerall versionsNo fix

Detection & mitigation playbook

Open-source dependency
  1. Detect

    Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @typespec/openapi3. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.

  2. Remediation status

    No patched version of @typespec/openapi3 has shipped for GHSA-2q42-4q24-7rgv yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.

  3. Mitigate without a patch

    If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.

  4. How O3 protects you

    O3 pinpoints whether GHSA-2q42-4q24-7rgv is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.

Tailored to GHSA-2q42-4q24-7rgv. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.

Frequently Asked Questions

### Summary The `@typespec/openapi3` emitter retains the value of a `@versioned` enum member and interpolates it into the output filename as `{version}` without sanitizing path separators or traversal components. The completed path reaches the compiler's `emitFile()`, which creates the parent directory and writes the file without verifying containment under `emitterOutputDir`. A crafted declarative `.tsp` input can therefore create or overwrite an OpenAPI-formatted `.yaml` or `.json` file outside the configured output tree, subject to the compiler process's filesystem permissions. No executa
O3 Security · Impact-Aware SCA

Is GHSA-2q42-4q24-7rgv in your dependencies?

O3 detects GHSA-2q42-4q24-7rgv across npm dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.

GHSA-2q42-4q24-7rgv: @typespec/openapi3… | O3 Security