CVE-2026-96754

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-25: 109-25
Referenced assets1 URL
By indicator
Full discourse1 post
  • ThreatAft@ThreatAft

    🚨 ORVAL — 3 × CVSS 9.8 CODE INJECTION • CVE-2026-96754 — @orval/hono path injection • CVE-2026-96755 — @orval/effect default injection • CVE-2026-96759 — TanStack Query operationId injection → https://threataft.com/articles/orval-mass-disclosure-cve-2026-96754-96755-96759 #Orval #CVE #RCE #PatchNow #CyberSecurity #ThreatIntel

    0000038
    44 followersView on X

Explore more