CVE-2026-96757: Improper Control of Generation of Code ('Code Injection') in orval-labs orval
orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications that executes when generated fetch operations or mock resolvers are invoked.
AI Analysis
Technical Summary
The vulnerability in orval before version 8.29.0 involves improper control of code generation, specifically a failure to escape OpenAPI media-type keys embedded in single-quoted Content-Type string literals. This enables attackers to craft OpenAPI specifications with malicious media-type keys that result in JavaScript code injection. The injected code executes in the context of generated fetch operations or mock resolvers, potentially leading to severe security consequences. The CVSS 4.0 base score is 9.3, indicating a critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary JavaScript code in the context of the generated client code without any privileges or user interaction. This can lead to complete compromise of the client environment where the generated code is executed, affecting confidentiality, integrity, and availability of the system or data.
Mitigation Recommendations
A fixed version of orval is available starting from version 8.29.0. Users should upgrade to orval 8.29.0 or later to remediate this vulnerability. Patch status is confirmed by the version range indicating affected versions are those before 8.29.0. No additional mitigations are specified.
CVE-2026-96757: Improper Control of Generation of Code ('Code Injection') in orval-labs orval
Description
orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications that executes when generated fetch operations or mock resolvers are invoked.
CVSS v4.0
Score 9.3critical
Affected software
orval-labs
orval
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in orval before version 8.29.0 involves improper control of code generation, specifically a failure to escape OpenAPI media-type keys embedded in single-quoted Content-Type string literals. This enables attackers to craft OpenAPI specifications with malicious media-type keys that result in JavaScript code injection. The injected code executes in the context of generated fetch operations or mock resolvers, potentially leading to severe security consequences. The CVSS 4.0 base score is 9.3, indicating a critical severity with network attack vector, no required privileges or user interaction, and high impact on confidentiality, integrity, and availability.
Potential Impact
Successful exploitation allows remote attackers to execute arbitrary JavaScript code in the context of the generated client code without any privileges or user interaction. This can lead to complete compromise of the client environment where the generated code is executed, affecting confidentiality, integrity, and availability of the system or data.
Mitigation Recommendations
A fixed version of orval is available starting from version 8.29.0. Users should upgrade to orval 8.29.0 or later to remediate this vulnerability. Patch status is confirmed by the version range indicating affected versions are those before 8.29.0. No additional mitigations are specified.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-23T15:58:30.841Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab402dcf7a7c541060ee0dc
Added to database: 09/23/2026, 16:48:28 UTC
Last enriched: 09/23/2026, 17:02:55 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.