An unpatched remote code execution vulnerability (CVE-2016-5641) in the Swagger API framework has been publicly disclosed. Swagger is a representation of RESTful API that allows developers to get interactive documentation, client SDK generation and discoverability. The vulnerability is easy to exploit due to the availability of a Metasploit module released by the security researcher Scott Davis. Injectable parameters in Swagger code generators allow attackers to remotely execute code across NodeJS, PHP, Ruby, and Java.”]
Source: http://securityaffairs.co/wordpress/48679/hacking/swagger-rce-flaw.html