{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/orval-8.14.0---8.28.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:orval:orval:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-96755"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["orval (8.14.0 - 8.28.1)","orval (\u003c 8.29.0)"],"_cs_severities":["critical"],"_cs_tags":["supply-chain","code-injection","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Orval"],"content_html":"\u003cp\u003eOrval versions 8.14.0 through 8.28.1 are affected by a code injection vulnerability located within the @orval/effect generator component. The vulnerability exists because the generator improperly processes OpenAPI schema default values, directly converting them into template literals within the generated output files. An attacker capable of influencing the OpenAPI definition - such as through a compromised API specification source or a malicious pull request - can embed arbitrary JavaScript expressions using the ${...} syntax. These expressions are subsequently evaluated at module scope when the generated code is built by a bundler or imported into a Node.js or browser environment. This vulnerability enables remote code execution during the build process or runtime, posing a critical risk to CI/CD pipelines and downstream applications consuming the generated client libraries.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution within the environment where the Orval-generated code is processed. This can lead to the compromise of CI/CD build environments, exfiltration of environment variables and secrets, or the injection of malicious code into the final application build. This vulnerability affects developers and organizations using Orval to generate client code from untrusted or externally sourced OpenAPI specifications.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Orval package to a version beyond 8.28.1 immediately to resolve CVE-2026-96755.\u003c/li\u003e\n\u003cli\u003eAudit all OpenAPI specification files currently being processed by Orval for any instances of ${...} syntax appearing within default values.\u003c/li\u003e\n\u003cli\u003eImplement strict validation and sanitization for OpenAPI files sourced from untrusted external contributors or third-party repositories before processing them with Orval.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T18:44:05Z","date_published":"2026-09-23T18:43:33Z","id":"https://feed.craftedsignal.io/briefs/2026-09-orval-code-injection/","summary":"Versions 8.14.0 through 8.28.1 of Orval contain a code injection vulnerability allowing arbitrary JavaScript execution via malicious OpenAPI schema defaults.","title":"Code Injection Vulnerability in Orval @orval/effect Generator","url":"https://feed.craftedsignal.io/briefs/2026-09-orval-code-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Orval (8.14.0 - 8.28.1)","version":"https://jsonfeed.org/version/1.1"}