Vulnerabilities/

HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis

Severity:
High

Description

Multiple functions conduct substring-only matching to validate hostnames to which basic authorization should be sent. An attacker can append the matched substrings to an attacker-controlled endpoint and capture authentication.

Recommendation

Update the @haxtheweb/open-apis package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@haxtheweb/open-apis
Anything's wrong? Let us know Last updated on June 09, 2026