{"id":"CVE-2026-96755","summary":"orval @orval/effect 8.14.0 through 8.28.1 Code Injection","details":"orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the generated code is built or imported.","aliases":["GHSA-q7f2-jg6j-r867"],"modified":"2026-09-25T03:48:29.066571719Z","published":"2026-09-23T16:23:52.011Z","database_specific":{"cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96755.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96755.json"},{"type":"ADVISORY","url":"https://github.com/orval-labs/orval/security/advisories/GHSA-q7f2-jg6j-r867"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96755"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/orval-orval-effect-8.14.0-through-8.28.1-code-injection"},{"type":"FIX","url":"https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23"},{"type":"FIX","url":"https://github.com/orval-labs/orval/pull/3995"},{"type":"PACKAGE","url":"https://github.com/orval-labs/orval"},{"type":"ARTICLE","url":"https://github.com/orval-labs/orval/blob/v8.28.1/packages/effect/src/index.ts#L298-L302"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/orval-labs/orval","events":[{"introduced":"43954fdc62eab13e4335a9d16c631a1312ebb5fd"},{"fixed":"3ea429d1161c0470cf34c08052821214ad908835"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"8.14.0"},{"fixed":"8.29.0"}]}}],"versions":["v8.28.1","v8.27.0","v8.26.0","v8.25.0","v8.24.0","v8.23.0","v8.22.0","v8.21.0","v8.20.0","v8.19.0","v8.18.0","v8.17.0","v8.16.0","v8.15.0","v8.14.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96755.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}