Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-96755: orval effect generator may run injected code

CVE-2026-96755 · published 5 days ago
Summary

The @orval/effect part of orval (versions 8.14.0 to 8.28.1) can execute malicious JavaScript that an attacker embeds in an API description. This happens when the tool turns certain default values into code, letting the attacker run code on your system when the generated files are built or loaded. Upgrade to a newer version of orval or stop using the affected generator until it is patched.

What to do
  • Update orval-labs orval to version 8.29.0 or later.
Affected software
VendorProductAffected versions
orval-labs orval < 8.29.0
Original advisory text
orval @orval/effect 8.14.0 through 8.28.1 Code Injection
orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the generated code is built or imported.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published23 Sep 2026
Updated27 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-96755 · MITRE
Track software like this
Free during beta