← Back to search

CVE-2026-96758

9.8 CRITICALpublic exploit available

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows code injection in the form-data serializer, enabling attackers to inject malicious ${...} expressions that can be executed during the generation of FormData bodies.
Exploitability
Exploitation is relatively straightforward given the preconditions of consumer process privileges. Attackers must have access to the affected version of the software.
Blast radius
If exploited, this vulnerability could lead to remote code execution and full control over the affected system or application.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to orval @orval/core 8.28.0 or later.
rcecode-injectionwebform-data

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live interpolation when the generated client builds FormData bodies with consumer process privileges.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-94

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.