PT-2026-97409 · Npm · Orval
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
orval versions prior to 8.30.0
Description
The @orval/core factory generator fails to escape date default values within
new Date() calls. This allows attackers to inject arbitrary expressions using apostrophes in OpenAPI schema defaults, leading to code execution with the privileges of the consumer process. This issue occurs when the factoryMethods and useDates options are enabled.Recommendations
Update orval to version 8.30.0 or later.
As a temporary mitigation, disable the
factoryMethods or useDates options.Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Orval