Code Injection Vulnerability in Orval by Orval Labs
CVE-2026-96756

9.2CRITICAL

Key Information:

Vendor

Orval-labs

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-96756?

Orval versions prior to 8.30.0 are susceptible to a code injection vulnerability in the @orval/core factory generator. This flaw arises from the inadequate escaping of default date values in new Date() calls within OpenAPI schema defaults. Attackers can exploit this vulnerability to inject arbitrary expressions using apostrophes, potentially allowing the execution of code under the privileges of the consumer process. This occurs specifically when the factoryMethods and useDates options are enabled, leading to significant security risks.

Affected Version(s)

orval 0 < 8.30.0

orval 8.30.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Enrik Mustafa
.