CVE-2026-96759

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript code through a crafted operationId in an OpenAPI specification that executes when generated hooks are called.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-25: 109-25
Referenced assets1 URL
By indicator
Full discourse1 post
  • ThreatAft@ThreatAft

    🚨 ORVAL — 3 × CVSS 9.8 CODE INJECTION • CVE-2026-96754 — @orval/hono path injection • CVE-2026-96755 — @orval/effect default injection • CVE-2026-96759 — TanStack Query operationId injection → https://threataft.com/articles/orval-mass-disclosure-cve-2026-96754-96755-96759 #Orval #CVE #RCE #PatchNow #CyberSecurity #ThreatIntel

    0000038
    44 followersView on X

Explore more