CVE-2026-96754: orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path

Published Sep 23, 2026
·
Updated

orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported.

Affected Software

1 affected component
npm/orval<8.29.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade orval/@orval/hono to a version that resolves this vulnerability.

    Fixed in 8.29.0

Event History

Sep 23, 2026
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which environments are exposed?

Projects using the @orval/hono generator in orval versions before 8.29.0 are affected when they generate code from an OpenAPI document containing a crafted static path segment.

2

What must an attacker control for exploitation?

An attacker must be able to supply or influence an OpenAPI document processed by the vulnerable generator. The document needs an apostrophe in a static path segment, and the generated TypeScript module must later be imported for the injected JavaScript to execute.

3

How can I determine whether generated code may be affected?

Check whether @orval/hono was used with an orval version before 8.29.0 and review the OpenAPI inputs used to generate affected modules. Pay particular attention to static path segments containing apostrophes and to generated modules that have been imported.

4

What is the available remediation?

Upgrade orval to version 8.29.0 or later. Regenerate affected TypeScript modules from trusted OpenAPI documents after upgrading.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203