Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-96754: orval @orval/hono may execute malicious code from crafted API spec
CVE-2026-96754 · published 5 days ago
Summary
If you use orval (versions before 8.29.0) to generate TypeScript code from an OpenAPI description, a specially crafted API file can cause the generated code to run unwanted JavaScript when it is loaded. This happens because the tool does not properly handle apostrophes in path names. Update to the latest version of orval or avoid using untrusted OpenAPI files to eliminate the risk.
What to do
- Update orval-labs orval to version 8.29.0 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| orval-labs | orval | < 8.29.0 |
Original advisory text
orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path
orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported.
References
- https://github.com/orval-labs/orval
- https://github.com/orval-labs/orval/blob/v8.28.1/packages/hono/src/index.ts#L169...
- https://github.com/orval-labs/orval/commit/155a5b7a38ff6886020cbc4c292db57c2793e...
- https://github.com/orval-labs/orval/pull/4006
- https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8d...
- https://github.com/orval-labs/orval/security/advisories/GHSA-g4mf-q5hw-f9j9
- https://www.vulncheck.com/advisories/orval-orval-hono-before-8.29.0-code-injecti...
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published23 Sep 2026
Updated29 Sep 2026
First seen23 Sep 2026
Track software like this
Free during beta