Poisoned Comments: Critical Orval Flaw (CVE-2026-25141) Injects Code
ID: 282b5824-bd4e-51d8-bdc3-f4ac09783572
STIX ID: report--282b5824-bd4e-51d8-bdc3-f4ac09783572
Feed Name: securityonline.info
Orval (a TypeScript client generator) has a critical code-injection vulnerability (CVE-2026-25141, CVSS 9.3) caused by improper sanitization of OpenAPI x-enum-descriptions; an attacker can include a closing comment sequence (*/ ) in a spec to inject executable code into generated clients, risking theft of environment variables, API keys, and arbitrary code execution. Maintainers have released patches and users are urged to upgrade and audit build pipelines, noting this bypasses a prior incomplete fix (CVE-2026-23947).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
