CVE-2026-96757: orval before 8.29.0 Code Injection via unescaped OpenAPI media-type

Published Sep 23, 2026
·
Updated

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications that executes when generated fetch operations or mock resolvers are invoked.

Affected Software

1 affected component
npm/orval<8.29.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade orval to a version that resolves this vulnerability.

    Fixed in 8.29.0

Event History

Sep 23, 2026
CVE Published
via MITRE·04:23 PM
Data Sourced
via MITRE·04:23 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are realistically exposed?

Projects using npm/orval versions before 8.29.0 are exposed if they generate code from an OpenAPI specification containing attacker-controlled media-type keys and later invoke the generated fetch operations or mock resolvers.

2

What must an attacker control for exploitation?

The attacker needs to supply or modify an OpenAPI specification with a crafted media-type key. No authentication or user interaction is required according to the provided severity vector.

3

When does the injected JavaScript execute?

The injected code executes when generated fetch operations or mock resolvers are invoked. Generating the code alone is not identified as the execution trigger.

4

How can I determine whether a project is affected?

Check whether the project uses an orval version earlier than 8.29.0 and whether its generated code was produced from OpenAPI specifications whose media-type keys may be untrusted or modified by attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203