Advisories for Golang/Github.com/Oapi-Codegen/Oapi-Codegen/V2 package

2026

oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code

The vulnerability in oapi-codegen seems to be similar with CVE-2026-22785, which is a generated-code injection issue where untrusted OpenAPI summary text is embedded into generated TypeScript MCP server source without proper escaping. oapi-codegen has a similar vulnerability in its server URL generator: untrusted OpenAPI servers[].description text is inserted into a generated Go line comment without normalizing embedded newlines. A crafted description can break out of the comment, add imports through …