PT-2026-5442 · Orval · Orval

K14Uz

·

Published

2026-01-21

·

Updated

2026-03-11

·

CVE-2026-25141

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Orval versions 7.19.0 through 7.20.9 Orval versions 8.0.0 through 8.1.9
Description Orval, a tool that generates type-safe JavaScript clients from OpenAPI specifications, is affected by a code injection issue. The jsStringEscape function does not adequately sanitize input, allowing attackers to inject and execute arbitrary JavaScript code using a limited set of characters, including []()!+. This is achieved through a technique known as JSFuck, which enables code execution without relying on alphanumeric characters or quotes.
Recommendations Update to Orval version 7.21.0 or later. Update to Orval version 8.2.0 or later.

Exploit

Fix

Command Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-25141
GHSA-GCH2-PHQH-FG9Q
GHSA-H526-WF6G-67JV

Affected Products

Orval