orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported. | |
| Title | orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path | |
| First Time appeared |
Orval
Orval orval |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:orval:orval:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Orval
Orval orval |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-23T16:23:51.012Z
Reserved: 2026-09-23T15:58:24.561Z
Link: CVE-2026-96754
No data.
Status : Received
Published: 2026-09-23T17:17:24.437
Modified: 2026-09-23T17:17:24.437
Link: CVE-2026-96754
No data.
OpenCVE Enrichment
Updated: 2026-09-23T17:30:06Z
Weaknesses