PT-2026-97411 · Npm · @Orval/Core

·

CVE-2026-96758

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @orval/core versions prior to 8.28.0
Description A code injection issue exists in the form-data serializer. The component fails to escape multipart property names within generated template literals. This allows attackers to inject ${...} expressions into OpenAPI schema property names, which are then executed as live interpolation when the generated client constructs FormData bodies using the privileges of the consumer process.
Recommendations Update @orval/core to version 8.28.0 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96758
GHSA-JWHM-6748-J6PQ

Affected Products

@Orval/Core