PT-2026-97410 · Npm · Orval

·

CVE-2026-96757

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions orval versions prior to 8.29.0
Description The software fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. This allows attackers to inject JavaScript via crafted media-type keys in OpenAPI specifications, which then executes when generated fetch operations or mock resolvers are invoked.
Recommendations Update orval to version 8.29.0 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96757
GHSA-4Q3X-RQFW-3X8P
GHSA-RCPR-MQ4M-JX9J

Affected Products

Orval