No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 23 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process when factoryMethods and useDates options are enabled. | |
| Title | orval before 8.30.0 Code Injection via Factory Generation | |
| First Time appeared |
Orval
Orval orval |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:orval:orval:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Orval
Orval orval |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-23T19:44:36.697Z
Reserved: 2026-09-23T15:58:25.631Z
Link: CVE-2026-96756
Updated: 2026-09-23T18:11:28.991Z
Status : Deferred
Published: 2026-09-23T17:17:24.767
Modified: 2026-09-23T20:17:27.057
Link: CVE-2026-96756
No data.
OpenCVE Enrichment
Updated: 2026-09-23T23:45:10Z