{"id":"CVE-2026-96754","published":"2026-09-23T17:17:24.437","lastModified":"2026-09-29T02:16:56.303","description":"orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://github.com/orval-labs/orval","tags":[]},{"url":"https://github.com/orval-labs/orval/blob/v8.28.1/packages/hono/src/index.ts#L169-L175","tags":[]},{"url":"https://github.com/orval-labs/orval/commit/155a5b7a38ff6886020cbc4c292db57c2793e6b6","tags":[]},{"url":"https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23","tags":[]},{"url":"https://github.com/orval-labs/orval/pull/4006","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-g4mf-q5hw-f9j9","tags":[]},{"url":"https://www.vulncheck.com/advisories/orval-orval-hono-before-8.29.0-code-injection-via-openapi-path","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-g4mf-q5hw-f9j9","tags":[]}],"exploitRefs":[{"url":"https://github.com/orval-labs/orval","tags":[]},{"url":"https://github.com/orval-labs/orval/blob/v8.28.1/packages/hono/src/index.ts#L169-L175","tags":[]},{"url":"https://github.com/orval-labs/orval/commit/155a5b7a38ff6886020cbc4c292db57c2793e6b6","tags":[]},{"url":"https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23","tags":[]},{"url":"https://github.com/orval-labs/orval/pull/4006","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-g4mf-q5hw-f9j9","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-g4mf-q5hw-f9j9","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows code injection by failing to escape OpenAPI path values, enabling arbitrary JavaScript code execution.","exploitability":"Exploitation is relatively straightforward with preconditions of an attacker-controlled OpenAPI document containing specific path segments.","blast_radius":"If exploited, this could lead to full system compromise, as arbitrary code execution can be achieved.","remediation":"Upgrade to orval version 8.29.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","code-injection","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:51:12.877Z"}}