VYPR

Orval

by Orval Labs

Source repositories

CVEs (22)

  • CVE-2026-96756HigSep 23, 2026
    risk 0.46cvss 8.1epss 0.00

    orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with…

  • CVE-2026-62680HigAug 19, 2026
    risk 0.39cvss 7.1epss 0.00

    Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. Processing an attacker-controlled OpenAPI…

Page 2 of 2