Code Injection Vulnerability in Orval by Orval Labs
CVE-2026-96756
9.2CRITICAL
What is CVE-2026-96756?
Orval versions prior to 8.30.0 are susceptible to a code injection vulnerability in the @orval/core factory generator. This flaw arises from the inadequate escaping of default date values in new Date() calls within OpenAPI schema defaults. Attackers can exploit this vulnerability to inject arbitrary expressions using apostrophes, potentially allowing the execution of code under the privileges of the consumer process. This occurs specifically when the factoryMethods and useDates options are enabled, leading to significant security risks.
Affected Version(s)
orval 0 < 8.30.0
orval 8.30.0
