PatchSiren cyber security CVE debrief
CVE-2026-96754 orval-labs CVE debrief
CVE-2026-96754 is a critical vulnerability in orval versions before 8.29.0, allowing for code injection via OpenAPI path values. The vulnerability exists in the @orval/hono generator, which fails to escape OpenAPI path values in single-quoted route literals. This allows attackers to craft OpenAPI documents with apostrophes in static path segments to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported.
- Vendor
- orval-labs
- Product
- orval
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-23
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-23
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for orval deployments should assess exposure and risk of code injection via OpenAPI path values. This includes verifying orval versions before 8.29.0 are not in use, assessing the risk of code injection, and upgrading to orval version 8.29.0 or later. Additionally, defenders should monitor for suspicious activity related to OpenAPI path values and review compensating controls for exposed systems.
Why it matters
CVE-2026-96754 is a critical vulnerability in orval versions before 8.29.0, allowing for code injection via OpenAPI path values. Defenders should prioritize verifying exposure and assessing the risk of code injection.
- Code injection via OpenAPI path values can lead to arbitrary JavaScript code execution
- Verification of orval versions before 8.29.0 is necessary to determine exposure
- Upgrading to orval version 8.29.0 or later can mitigate the vulnerability
- Monitoring for suspicious activity related to OpenAPI path values is recommended
Technical summary
The @orval/hono generator fails to escape OpenAPI path values in single-quoted route literals, allowing attackers to craft OpenAPI documents with apostrophes in static path segments to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported. This vulnerability exists in orval versions before 8.29.0 and allows for code injection via OpenAPI path values. The vulnerability can be mitigated by upgrading to orval version 8.29.0 or later. Defenders should prioritize verifying exposure of orval versions before 8.29.0 and assessing the risk of code injection via OpenAPI path values.
Defensive priority
Defenders should prioritize verifying exposure of orval versions before 8.29.0 and assessing the risk of code injection via OpenAPI path values.
Recommended defensive actions
- Verify orval versions before 8.29.0 are not in use
- Assess the risk of code injection via OpenAPI path values
- Upgrade to orval version 8.29.0 or later
- Monitor for suspicious activity related to OpenAPI path values
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source references provide details on the vulnerability, including its existence in orval versions before 8.29.0 and the possibility of code injection via OpenAPI path values. The @orval/hono generator fails to escape OpenAPI path values in single-quoted route literals, allowing attackers to craft OpenAPI documents with apostrophes in static path segments to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported. Defenders should verify exposure and assess the risk of code. Or
Sources and references
Verified primary and authoritative sources
-
CVE-2026-96754 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-96754
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-96754 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-96754
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/orval-labs/orval
-
Source reference
Unverified legacy reference
URL: https://github.com/orval-labs/orval/blob/v8.28.1/packages/hono/src/index.ts
-
Source reference
Unverified legacy reference
URL: https://github.com/orval-labs/orval/commit/155a5b7a38ff6886020cbc4c292db57c2793e6b6
-
Source reference
Unverified legacy reference
URL: https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23
-
Source reference
Unverified legacy reference
URL: https://github.com/orval-labs/orval/pull/4006
-
Source reference
Unverified legacy reference
URL: https://github.com/orval-labs/orval/security/advisories/GHSA-g4mf-q5hw-f9j9
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/orval-orval-hono-before-8.29.0-code-injection-via-openapi-path
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.