PT-2026-5442 · Orval · Orval

K14Uz

·

Publicado

2026-01-21

·

Atualizado

2026-03-11

·

CVE-2026-25141

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Orval versions 7.19.0 through 7.20.9 Orval versions 8.0.0 through 8.1.9
Description Orval, a tool that generates type-safe JavaScript clients from OpenAPI specifications, is affected by a code injection issue. The jsStringEscape function does not adequately sanitize input, allowing attackers to inject and execute arbitrary JavaScript code using a limited set of characters, including []()!+. This is achieved through a technique known as JSFuck, which enables code execution without relying on alphanumeric characters or quotes.
Recommendations Update to Orval version 7.21.0 or later. Update to Orval version 8.2.0 or later.

Exploit

Correção

Command Injection

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-25141
GHSA-GCH2-PHQH-FG9Q
GHSA-H526-WF6G-67JV

Produtos afetados

Orval