CVE-2026-25141Disclosure(orval / orval)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch orval orval systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7.21.0 and 8.2.0 have an incomplete fix for CVE-2026-23947. While the jsStringEscape function properly handles single quotes ('), double quotes (") and so on, it is still possible to achieve code injection using only a limited set of characters that are currently not escaped. The vulnerability lies in the fact that the application can be forced to execute arbitrary JavaScript using characters such as []()!+. By using a technique known as JSFuck, an attacker can bypass the current sanitization logic and run arbitrary code without needing any alphanumeric characters or quotes. Version 7.21.0 and 8.2.0 contain an updated fix.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • orval

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-01-30); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
orval

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-01-30: 2Mentions · 2026-02-04: 1Mentions · 2026-03-11: 1PoC Mentioned / Linked · 2026-01-30: 1PoC Mentioned / Linked · 2026-02-04: 1PoC Mentioned / Linked · 2026-03-11: 1Exploit Tool / Code · 2026-01-30: 1Patch / Workaround · 2026-01-30: 1Technical Details · 2026-01-30: 2Technical Details · 2026-03-11: 101-3002-0403-11
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-302
Disclosure1Patch1
2026-02-041
Disclosure1
2026-03-111
Disclosure1
Full discourse4 posts
  • Komodo Cyber Security@Komodosec
    Disclosure

    #VulnerabilityReport #codeinjection Poisoned Comments: Critical Orval Flaw (CVE-2026-25141) Injects Code https://securityonline.info/poisoned-comments-critical-orval-flaw-cve-2026-25141-injects-code/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces the discovery of a code‑injection vulnerability, CVE‑2026‑25141, and provides a link for further details.

    0000036
    1.5K followersView on X
  • Karma-X@Karma_X_Inc
    Disclosure

    Poisoned Comments: Critical Orval Flaw (CVE-2026-25141) Injects Code https://securityonline.info/poisoned-comments-critical-orval-flaw-cve-2026-25141-injects-code/

    Post summary

    The text announces a new critical vulnerability (CVE-2026-25141) in Orval that permits code injection via comments, linking to a detailed post, but it does not provide exploit code, patches, or evidence of active exploitation.

    0000032
    73 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25141 Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7.21.0 and 8.2.0 h… https://www.cve.org/CVERecord?id=CVE-2026-25141

    Post summary

    The notice announces CVE-2026-25141 as affecting specific Orval releases, providing affected version ranges but no exploitation or mitigation details.

    00000169
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Patch

    🚨 CVE-2026-25141: Orval has a code injection via u... JSFuck-based code injection in Orval bypasses sanitization with []()!+ chars - patch now or watch your API clients beco... https://zerodaysignal.com/vulnerability/CVE-2026-25141 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a code injection vulnerability in Orval, details the JSFuck-based exploitation method, and urges users to apply a patch to protect their API clients.

    0000055
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporvalorval---

Explore more