← Back to search

CVE-2026-96757

9.8 CRITICALpublic exploit available

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows attackers to inject JavaScript by exploiting crafted media-type keys in OpenAPI specifications, leading to remote code execution.
Exploitability
Exploitation is relatively easy given the preconditions of an affected version and a crafted OpenAPI specification.
Blast radius
If exploited, the impact could be severe, as it allows remote code execution, potentially leading to full system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to orval 8.29.0 or later.
rcewebapisecurity

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications that executes when generated fetch operations or mock resolvers are invoked.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.