orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process when factoryMethods and useDates options are enabled.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process when factoryMethods and useDates options are enabled. | |
| Title | orval before 8.30.0 Code Injection via Factory Generation | |
| First Time appeared |
Orval
Orval orval |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:orval:orval:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Orval
Orval orval |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-23T16:23:53.491Z
Reserved: 2026-09-23T15:58:25.631Z
Link: CVE-2026-96756
No data.
Status : Received
Published: 2026-09-23T17:17:24.767
Modified: 2026-09-23T17:17:24.767
Link: CVE-2026-96756
No data.
OpenCVE Enrichment
No data.
Weaknesses