CRITICAL 9.3 NVD
CVE-2026-96758
orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated t
orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live interpolation when the generated client builds FormData bodies with consumer process privileges.
References
- https://github.com/orval-labs/orval
- https://github.com/orval-labs/orval/blob/v8.27.0/packages/core/src/getters/res-req-types.t
- https://github.com/orval-labs/orval/commit/975a769a76151354dead879feadfa3537ff065fe
- https://github.com/orval-labs/orval/pull/3988
- https://github.com/orval-labs/orval/security/advisories/GHSA-jwhm-6748-j6pq
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-23 via NVD.
Risk Timeline
CVE Disclosed2026-09-23 · -1 days ago
Remediation Resources
vulnfeed aggregates 12908 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.