logo

Poisoned Comments: Critical Orval Flaw (CVE-2026-25141) Injects Code

ID: 282b5824-bd4e-51d8-bdc3-f4ac09783572

STIX ID: report--282b5824-bd4e-51d8-bdc3-f4ac09783572

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-04

Date Updated: 2026-04-23

Author: Ddos

...
...

Orval (a TypeScript client generator) has a critical code-injection vulnerability (CVE-2026-25141, CVSS 9.3) caused by improper sanitization of OpenAPI x-enum-descriptions; an attacker can include a closing comment sequence (*/ ) in a spec to inject executable code into generated clients, risking theft of environment variables, API keys, and arbitrary code execution. Maintainers have released patches and users are urged to upgrade and audit build pipelines, noting this bypasses a prior incomplete fix (CVE-2026-23947).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.