Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process when factoryMethods and useDates options are enabled. | |
| Title | orval before 8.30.0 Code Injection via Factory Generation | |
| First Time appeared |
Orval
Orval orval |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:orval:orval:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Orval
Orval orval |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-23T19:44:36.697Z
Reserved: 2026-09-23T15:58:25.631Z
Link: CVE-2026-96756
Updated: 2026-09-23T18:11:28.991Z
Status : Deferred
Published: 2026-09-23T17:17:24.767
Modified: 2026-09-23T20:17:27.057
Link: CVE-2026-96756
No data.
OpenCVE Enrichment
Updated: 2026-09-23T17:45:07Z