PT-2026-3522 · Orval · Orval

K14Uz

·

Published

2026-01-20

·

Updated

2026-02-27

·

CVE-2026-23947

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Orval versions 7.10.0 through 8.0.2
Description Orval, a tool for generating type-safe JavaScript clients from OpenAPI specifications, is affected by an arbitrary code execution issue. Untrusted OpenAPI specifications can inject arbitrary TypeScript/JavaScript code into generated clients through the x-enumDescriptions field. This injection occurs during const enum generation within the getEnumImplementation() function, resulting in executable code within the generated schema files. This issue is similar to, but distinct from, a previously addressed issue.
Recommendations Update to a version later than 8.0.2.

Exploit

Fix

RCE

Code Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-23947
GHSA-H526-WF6G-67JV

Affected Products

Orval