{"id":"CVE-2026-96758","published":"2026-09-23T17:17:25.083","lastModified":"2026-09-23T19:19:54.890","description":"orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live interpolation when the generated client builds FormData bodies with consumer process privileges.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-94"],"vendors":[],"products":[],"references":[{"url":"https://github.com/orval-labs/orval","tags":[]},{"url":"https://github.com/orval-labs/orval/blob/v8.27.0/packages/core/src/getters/res-req-types.ts#L808","tags":[]},{"url":"https://github.com/orval-labs/orval/commit/975a769a76151354dead879feadfa3537ff065fe","tags":[]},{"url":"https://github.com/orval-labs/orval/pull/3988","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-jwhm-6748-j6pq","tags":[]},{"url":"https://www.vulncheck.com/advisories/orval-orval-core-before-8.28.0-code-injection-via-form-data","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-jwhm-6748-j6pq","tags":[]}],"exploitRefs":[{"url":"https://github.com/orval-labs/orval","tags":[]},{"url":"https://github.com/orval-labs/orval/blob/v8.27.0/packages/core/src/getters/res-req-types.ts#L808","tags":[]},{"url":"https://github.com/orval-labs/orval/commit/975a769a76151354dead879feadfa3537ff065fe","tags":[]},{"url":"https://github.com/orval-labs/orval/pull/3988","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-jwhm-6748-j6pq","tags":[]},{"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-jwhm-6748-j6pq","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows code injection in the form-data serializer, enabling attackers to inject malicious ${...} expressions that can be executed during the generation of FormData bodies.","exploitability":"Exploitation is relatively straightforward given the preconditions of consumer process privileges. Attackers must have access to the affected version of the software.","blast_radius":"If exploited, this vulnerability could lead to remote code execution and full control over the affected system or application.","remediation":"Upgrade to orval @orval/core 8.28.0 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","code-injection","web","form-data"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:51:27.397Z"}}