Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-96756: orval before 8.30.0 lets attackers run code

CVE-2026-96756 · published 5 days ago
Summary

Versions of the orval tool released before 8.30.0 can be tricked into executing unwanted commands when it processes certain API specifications. By inserting special characters into default date values, an attacker could cause the tool to run code with the same rights as the user running it. Update to version 8.30.0 or later, or disable the factory generation options that use dates, to eliminate the risk.

What to do
  • Update orval-labs orval to version 8.30.0 or later.
Affected software
VendorProductAffected versions
orval-labs orval < 8.30.0
Original advisory text
orval before 8.30.0 Code Injection via Factory Generation
orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process when factoryMethods and useDates options are enabled.
Severity
9.2 Critical
CVSS 3.1: 8.1 (NVD)
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published23 Sep 2026
Updated29 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-96756 · MITRE
Track software like this
Free during beta