Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-71867: orval package could let attackers run code

CVE-2026-71867 · published 8 days ago
Summary

The orval software used in several npm packages can be tricked into executing unwanted code. This could let a malicious user take control of your system or data. Update to the latest released versions of the affected orval packages as soon as possible.

What to do
  • Update melloware orval to version 8.21.0.
  • Update orval to version 8.21.0.
  • Update orval to version 7.13.2-aikido.1.
  • Update rootio @rootio/orval to version 7.13.2-root.io.1.
  • Update orval to version 7.21.0-aikido.2.
  • Update rootio @rootio/orval to version 7.21.0-root.io.2.
  • Update orval to version 7.21.0-aikido.3.
  • Update rootio @rootio/orval to version 7.21.0-root.io.3.
Affected software
Ecosystem VendorProductAffected versions
– orval-labs orval < 8.21.0
npm melloware orval < 8.21.0
Fix: upgrade to 8.21.0
npm – orval < 8.21.0
Fix: upgrade to 8.21.0
Root:npm – orval < 7.13.2-aikido.1
< 7.21.0-aikido.2
< 7.21.0-aikido.3
Fix: upgrade to 7.13.2-aikido.1
Root:npm rootio @rootio/orval < 7.13.2-root.io.1
< 7.21.0-root.io.2
< 7.21.0-root.io.3
Fix: upgrade to 7.13.2-root.io.1
Original advisory text
CVE-2026-71867 in orval - Patched by Root
Root has patched CVE-2026-71867 in the orval package for Root:npm. Multiple fixed versions available.
Severity
9.3 Critical
Exploitation
EPSS <1%
Type
CWE-89SQL Injection
CWE-95Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Timeline
Published21 Sep 2026
Updated27 Sep 2026
First seen19 Aug 2026
Track software like this
Free during beta