Code Injection Vulnerability in Orval OpenAPI Client by Orval Labs
CVE-2026-96759
9.3CRITICAL
What is CVE-2026-96759?
The vulnerable Orval OpenAPI Client prior to version 8.29.0 does not properly escape the operationId parameter, enabling attackers to inject arbitrary JavaScript code. This code executes while calling generated hooks, posing a significant security risk when using crafted OpenAPI specifications.
Affected Version(s)
orval 0 < 8.29.0
orval 8.29.0
