{"id":"CVE-2026-96755","published":"2026-09-23T17:17:24.607","lastModified":"2026-09-23T18:16:08.337","description":"orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the generated code is built or imported.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://github.com/orval-labs/orval","tags":[]},{"url":"https://github.com/orval-labs/orval/blob/v8.28.1/packages/effect/src/index.ts#L298-L302","tags":[]},{"url":"https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23","tags":[]},{"url":"https://github.com/orval-labs/orval/pull/3995","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-q7f2-jg6j-r867","tags":[]},{"url":"https://www.vulncheck.com/advisories/orval-orval-effect-8.14.0-through-8.28.1-code-injection","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-q7f2-jg6j-r867","tags":[]}],"exploitRefs":[{"url":"https://github.com/orval-labs/orval","tags":[]},{"url":"https://github.com/orval-labs/orval/blob/v8.28.1/packages/effect/src/index.ts#L298-L302","tags":[]},{"url":"https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23","tags":[]},{"url":"https://github.com/orval-labs/orval/pull/3995","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-q7f2-jg6j-r867","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-q7f2-jg6j-r867","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows attackers to inject arbitrary JavaScript expressions via OpenAPI schema defaults, leading to remote code execution.","exploitability":"Exploitation is relatively straightforward given the presence of ${...} syntax in schema defaults. Precondition is the use of orval versions 8.14.0 through 8.28.1.","blast_radius":"If exploited, this vulnerability could lead to full compromise of the affected system, including execution of arbitrary code.","remediation":"Upgrade to orval version 8.29.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","code-injection"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:51:17.870Z"}}