Code Injection Vulnerability in orval by orval-labs
CVE-2026-96755
9.3CRITICAL
What is CVE-2026-96755?
Versions of orval from 8.14.0 to 8.28.1 are susceptible to a code injection issue in the @orval/effect generator. This vulnerability arises when OpenAPI schema defaults utilize the ${...} syntax, allowing attackers to inject arbitrary JavaScript expressions. The injected code is executed at module scope during the code's build or import process, potentially compromising application security.
Affected Version(s)
orval 8.14.0 < 8.29.0
orval 8.29.0
