{"id":"CVE-2026-96755","aliases":["GHSA-q7f2-jg6j-r867"],"url":"https://o3.security/vulnerability/CVE-2026-96755","summary":"orval @orval/effect 8.14.0 through 8.28.1 Code Injection","details":"orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the generated code is built or imported.","published":"2026-09-23T16:23:52.011Z","modified":"2026-09-24T03:47:08.265647085Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23","label":"orval-labs/orval@d346d94"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96755.json"},{"type":"PACKAGE","url":"https://github.com/orval-labs/orval"},{"type":"ARTICLE","url":"https://github.com/orval-labs/orval/blob/v8.28.1/packages/effect/src/index.ts#L298-L302"},{"type":"FIX","url":"https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23"},{"type":"FIX","url":"https://github.com/orval-labs/orval/pull/3995"},{"type":"ADVISORY","url":"https://github.com/orval-labs/orval/security/advisories/GHSA-q7f2-jg6j-r867"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96755"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/orval-orval-effect-8.14.0-through-8.28.1-code-injection"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-24T03:47:08.265647085Z"}}