CVE-2026-96755

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the generated code is built or imported.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-25: 109-25
Referenced assets1 URL
By indicator
Full discourse1 post
  • ThreatAft@ThreatAft

    🚨 ORVAL — 3 × CVSS 9.8 CODE INJECTION • CVE-2026-96754 — @orval/hono path injection • CVE-2026-96755 — @orval/effect default injection • CVE-2026-96759 — TanStack Query operationId injection → https://threataft.com/articles/orval-mass-disclosure-cve-2026-96754-96755-96759 #Orval #CVE #RCE #PatchNow #CyberSecurity #ThreatIntel

    0000038
    44 followersView on X

Explore more