VYPR

Orval

by Orval Labs

Source repositories

CVEs (22)

  • CVE-2026-96759CriSep 23, 2026
    risk 0.57cvss 9.8epss 0.00

    orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript code through a crafted operationId in an OpenAPI specification that executes when generated…

  • CVE-2026-96758CriSep 23, 2026
    risk 0.57cvss 9.8epss 0.01

    orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live…

  • CVE-2026-96757CriSep 23, 2026
    risk 0.57cvss 9.8epss 0.01

    orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications that executes when generated fetch…

  • CVE-2026-96755CriSep 23, 2026
    risk 0.57cvss 9.8epss 0.00

    orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are…

  • CVE-2026-96754CriSep 23, 2026
    risk 0.57cvss 9.8epss 0.00

    orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary…

  • CVE-2026-25141CriJan 30, 2026
    risk 0.57cvss 9.8epss 0.01

    Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7.21.0 and 8.2.0 have an incomplete fix for CVE-2026-23947. While the jsStringEscape function properly handles single quotes ('),…

  • CVE-2026-24132CriJan 23, 2026
    risk 0.57cvss 9.8epss 0.01

    Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions 7.19.0 and below and 8.0.0-rc.0 through 8.0.2 allow untrusted OpenAPI specifications to inject arbitrary TypeScript/JavaScript into generated mock files via the…

  • CVE-2026-23947CriJan 20, 2026
    risk 0.57cvss 9.8epss 0.01

    Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vulnerable to arbitrary code execution in environments consuming generated clients. This issue is similar in nature to…

  • CVE-2026-22785CriJan 12, 2026
    risk 0.57cvss 9.8epss 0.01

    orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation logic relies on string manipulation that incorporates the summary field from the OpenAPI specification without proper validation or…

  • CVE-2026-72717CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template literal emitted by zod schema generation without safe encoding.…

  • CVE-2026-72716CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query parameter default is emitted into a module-level template literal emitted by zod schema generation without safe…

  • CVE-2026-71871CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into a module-level template literal emitted by zod schema generation without safe…

  • CVE-2026-71869CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template literal emitted by zod schema generation without safe…

  • CVE-2026-71868CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-level template literal emitted by zod schema generation without safe encoding.…

  • CVE-2026-71867CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories without safe encoding. This permits…

  • CVE-2026-71866CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema property name is emitted into the generated zod.object({...}) schema without safe encoding. This permits…

  • CVE-2026-71865CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a query parameter name is emitted into the generated request-validation zod.object({...}) schema without safe encoding. This permits…

  • CVE-2026-71864CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header parameter name is emitted into the generated request-validation zod.object({...}) schema without safe encoding. This permits…

  • CVE-2026-62682CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into request URL template literals generated when output.baseUrl.getBaseUrlFromSpecification is enabled…

  • CVE-2026-62681CriAug 19, 2026
    risk 0.54cvss —epss 0.01

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch, react-query, and SWR clients without safe…

Page 1 of 2