SCA: security update for @orpc/openapi (GHSA-7f6v-3gx7-27q8)

medium Tenable Cloud Security Plugin ID 439057

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- oRPC is an tool that helps build APIs that are end-to-end type-safe and adhere to OpenAPI standards. Prior
to version 1.13.9, a stored cross-site scripting (XSS) vulnerability exists in the OpenAPI documentation
generation of orpc. If an attacker can control any field within the OpenAPI specification (such as
info.description), they can break out of the JSON context and execute arbitrary JavaScript when a user
views the generated API documentation. This issue has been patched in version 1.13.9. (CVE-2026-33331)

Solution

Update the @orpc/openapi library and its related packages to version 1.13.9 or later.

See Also

https://github.com/advisories/GHSA-7f6v-3gx7-27q8

Plugin Details

Severity: Medium

ID: 439057

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 3/20/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.3

Percentile: 9.42

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-33331

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/20/2026

Vulnerability Publication Date: 3/20/2026

Reference Information

CVE: CVE-2026-33331

cwe: CWE-79