Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-96758: orval core can run malicious code through form data

CVE-2026-96758 · published 5 days ago
Summary

The orval core library (versions before 8.28.0) can be tricked into executing unwanted code when it builds multipart form data. This happens if an attacker places special placeholders in the names of fields defined in an OpenAPI description. Update to the latest version of orval core to stop this behavior.

What to do
  • Update orval-labs orval to version 8.28.0 or later.
Affected software
VendorProductAffected versions
orval-labs orval < 8.28.0
Original advisory text
orval @orval/core before 8.28.0 Code Injection via Form-Data
orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live interpolation when the generated client builds FormData bodies with consumer process privileges.
Severity
9.3 Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published23 Sep 2026
Updated29 Sep 2026
First seen23 Sep 2026
Sources
CVE-2026-96758 · MITRE
Track software like this
Free during beta