Security Flaw in oasdiff-action GitHub Action Affects OpenAPI Specifications
CVE-2026-53507
8.3HIGH
What is CVE-2026-53507?
The oasdiff-action, a GitHub Action for detecting breaking changes in OpenAPI specifications, contains a vulnerability that allows malicious actors to exploit external references in OpenAPI specs. Prior to version 0.0.51, the action resolved external $refs automatically, which could lead to Server-Side Request Forgery (SSRF) attacks when processing attacker-controlled pull requests. This vulnerability can expose sensitive data from the runner environment without any interaction, making it crucial for users to upgrade to the patched version to safeguard against unauthorized data access.
Affected Version(s)
oasdiff-action < 0.0.51
