PT-2026-97412 · Npm · Orval

·

CVE-2026-96759

·

Published

2026-09-23

·

Updated

2026-09-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions orval versions prior to 8.29.0
Description The software fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. This allows attackers to inject arbitrary JavaScript code via a crafted operationId within an OpenAPI specification, which then executes when the generated hooks are called.
Recommendations Update orval to version 8.29.0 or later.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96759
GHSA-VV88-CM6J-665J

Affected Products

Orval