maven package report

Is io.swagger:swagger-codegen safe?

4 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
1.6%

chance of exploitation in the next 30 days

xyz score
3.4

CyberXYZ composite, out of 10

fig. 01 — GHSA-vgvf-9jh3-fg75, the advisory selected below

// advisories

GHSA-vgvf-9jh3-fg75

HIGHCVE-2017-1000207

A vulnerability in Swagger-Parser's version <= 1.0.30 and Swagger codegen version <= 2.2.2 yaml parsing functionality results in arbitrary code being executed when a maliciously crafted yaml Open-API specification is parsed. This in particular, affects the 'generate' and 'validate' command in swagger-codegen (<= 2.2.2) and can lead to arbitrary code being executed when these commands are used on a

Affected
< 2.2.2
Fixed in
2.2.2
Weakness
CWE-502
Published
2018-10-19
Source
github

GHSANVDMITREreferencereference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.


Checked 2026-09-22 at 03:31 UTC. The most recent advisory here was published 2021-03-11. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is io.swagger:swagger-codegen safe? maven package security report | CyberXYZ