CVE-2026-96756
9.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process when factoryMethods and useDates options are enabled.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| orval-labs | orval | 0 < 8.30.0 | affected |
| orval-labs | orval | 8.30.0 | unaffected |
Weaknesses
- CWE-94: Improper Control of Generation of Code ('Code Injection')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
- https://github.com/orval-labs/orval/security/advisories/GHSA-wx66-36r6-v5g7
- https://github.com/orval-labs/orval/pull/4038
- https://github.com/orval-labs/orval/commit/b9b083576943c683540200eb957feced57dddc1a
- https://github.com/orval-labs/orval/blob/v8.29.0/packages/core/src/generators/factory.ts#L493
- https://github.com/orval-labs/orval
- https://www.vulncheck.com/advisories/orval-before-8.30.0-code-injection-via-factory-generation
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.