
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>TheGriffyn</title>
      <link>https://thegriffyn.me/blog</link>
      <description>Cybersecurity blog by Hamza Haroon - penetration testing write-ups, CTF solutions, CVEs, digital forensics, and threat intelligence research.</description>
      <language>en-us</language>
      <managingEditor>hamzaharooon@protonmail.com (Hamza Haroon)</managingEditor>
      <webMaster>hamzaharooon@protonmail.com (Hamza Haroon)</webMaster>
      <lastBuildDate>Tue, 16 Jun 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://thegriffyn.me/tags/supply-chain/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://thegriffyn.me/blog/oss/six-cves-in-swagger-typescript-api</guid>
    <title>Six CVEs, Four RCEs, One npm Package: Inside swagger-typescript-api&#39;s Supply-Chain Risk</title>
    <link>https://thegriffyn.me/blog/oss/six-cves-in-swagger-typescript-api</link>
    <description>swagger-typescript-api, one of npm&#39;s most-used OpenAPI-to-TypeScript client generators (~600K downloads/week), shipped four RCE CVEs, an SSRF, and an authorization-token exfiltration. Here&#39;s how a single attacker-controlled OpenAPI spec turns a code generator into remote code execution.</description>
    <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
    <author>hamzaharooon@protonmail.com (Hamza Haroon)</author>
    <category>security</category><category>supply-chain</category><category>rce</category><category>ssrf</category><category>openapi</category><category>typescript</category><category>cve</category><category>code-execution</category>
  </item>

    </channel>
  </rss>
