logo

Supply Chain Alert: Critical Code Injection Flaw (CVSS 9.3) in Orval

ID: fe5073c7-6c5c-5e8b-8cc6-19f0c11dbbb9

STIX ID: report--fe5073c7-6c5c-5e8b-8cc6-19f0c11dbbb9

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-22

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical code-injection vulnerability (CVE-2026-23947) was discovered in the Orval tool used to generate TypeScript clients from OpenAPI specs: unescaped x-enum-descriptions fields in untrusted specifications can inject arbitrary TypeScript/JavaScript into generated client files, leading to arbitrary code execution in applications that consume those clients; maintainers have released a patch and users should upgrade to Orval 8.0.2 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.