These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-23T17:17:25.250Z and has not been modified since then. CVE-2026-96759 is a critical vulnerability in orval before version 8.29.0, allowing for potential JavaScript code injection through crafted operationId parameters in OpenAPI specifications. This vulnerability impacts orval users who process Open [truncated]
CVE-2026-96754 is a critical vulnerability in orval versions before 8.29.0, allowing for code injection via OpenAPI path values. The vulnerability exists in the @orval/hono generator, which fails to escape OpenAPI path values in single-quoted route literals. This allows attackers to craft OpenAPI documents with apostrophes in static path segments to inject arbitrary JavaScript code that executes when the [truncated]
The CVE-2026-72717 issue involves a critical vulnerability in Orval, a library used to generate type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. The vulnerability permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. This occurs due [truncated]
A critical vulnerability in Orval, a tool for generating type-safe JavaScript clients from OpenAPI v3 and Swagger v2 specifications, allows for code execution in developer, CI, test, or application environments. The issue arises from the unsafe emission of attacker-controlled JavaScript in a module-level template literal during zod schema generation. This occurs when a ${...} expression or backtick is pre [truncated]
The CVE-2026-71871 issue affects Orval, a library that generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. The vulnerability exists in the packages/zod/src/index.ts file, specifically in the formatDefaultValue function, which improperly handles ${...} expressions or backticks in header parameter defaults. This permits attacker-controlled JavaScript to be eva [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T18:17:24.413Z and has not been modified since then. The CVE-2026-71868 issue is a critical vulnerability in Orval, a tool for generating type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to version 8.21.0, a ${...} expression or backtick in an enum de [truncated]
CVE-2026-71867 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated mock factory is called by tests or an MSW handler, re [truncated]
A critical vulnerability in Orval, a tool for generating type-safe JavaScript clients from OpenAPI and Swagger specifications, allows for code execution when importing generated zod schema modules. The issue arises from a double quote in a schema property name being emitted into the generated zod.object({...}) schema without safe encoding, permitting attacker-controlled JavaScript evaluation. This affects [truncated]
Orval, a type-safe JavaScript client generator, has a critical vulnerability (CVE-2026-71865) allowing code execution in developer, CI, test, or application environments. The issue arises from a double quote in a query parameter name being emitted into the generated request-validation zod.object({...}) schema without safe encoding. This vulnerability is fixed in version 8.21.0. Developers and users of Orv [truncated]
The CVE-2026-71864 vulnerability affects Orval, a library used to generate type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. The vulnerability, with a CVSS score of 9.3 and classified as CRITICAL, permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported. This results in code execution in the developer, CI, test, or appl [truncated]
A critical vulnerability in Orval, a tool for generating type-safe JavaScript clients from OpenAPI and Swagger specifications, allows for code execution in developer, CI, test, or application environments. The issue arises from an unescaped backtick in the servers[0].url being emitted into request URL template literals, permitting attacker-controlled JavaScript evaluation when a generated request or URL-b [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T18:16:54.383Z and has not been modified since then. The NVD entry is currently Received. Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literal [truncated]
CVE-2026-62680 is a vulnerability in Orval, a tool for generating type-safe JavaScript clients from OpenAPI v3 and Swagger v2 specifications. Prior to version 8.22.0, Orval resolves remote and local external $ref values without proper confinement, allowing for potential SSRF and file reads. The issue is fixed in version 8.22.0. Affected product deployments should be identified and assessed for exposure. T [truncated]