Code Injection Vulnerability in Orval by Orval Labs
CVE-2026-96757
9.3CRITICAL
What is CVE-2026-96757?
A vulnerability exists in Orval versions prior to 8.29.0, where the application fails to properly escape media-type keys in OpenAPI specifications. This oversight can lead to the injection of malicious JavaScript code when such keys are emitted into single-quoted Content-Type string literals during code generation. When affected fetch operations or mock resolvers are executed, the injected code can run, posing significant security risks.
Affected Version(s)
orval 6.7.1 < 8.29.0
orval 8.29.0
