CVE-2026-96754
📛 CVE Title
orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path
Description
orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- VulnCheck
- CVSS severity
- CRITICAL
- CVSS score
- 9.3 / 10
- CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N- Effective score
- 9.3 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-94 - Reserved
- 2026-09-23
- Published
- 2026-09-23 16:23 UTC
- Last updated
- 2026-09-23 16:23 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/96xxx/CVE-2026-96754.json
- Linked Threat
- CVE-2026-96754 — orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-09-23 17:17:24 UTC
- NVD last modified
- 2026-09-23 17:17:24 UTC
- NVD CVSS v3.1
- 9.8 / 10 CRITICAL source: disclosure@vulncheck.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 5.9 / 10
NVD / KEV / EPSS data refreshed 2026-09-24 04:23 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-85404 - Assigner
- VulnCheck
- Published
- Sep 23, 2026, 4:23:51 PM
- Updated
- Sep 23, 2026, 4:23:51 PM
- EUVD base score (CVSS 4.0)
-
9.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N - EUVD-reported EPSS
- 0.0000
- Vendors
- orval-labs
- Products
-
orval (0 <8.29.0)
- Aliases
-
GHSA-4p56-cvjx-38fv
ENISA description: orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported.
EUVD references (7)
- https://github.com/orval-labs/orval/security/advisories/GHSA-g4mf-q5hw-f9j9
- https://github.com/orval-labs/orval/pull/4006
- https://github.com/orval-labs/orval/commit/155a5b7a38ff6886020cbc4c292db57c2793e6b6
- https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23
- https://github.com/orval-labs/orval/blob/v8.28.1/packages/hono/src/index.ts#L169-L175
- https://github.com/orval-labs/orval
- https://www.vulncheck.com/advisories/orval-orval-hono-before-8.29.0-code-injection-via-openapi-path
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| orval-labs | orval |
0 (affected),
8.29.0 (unaffected)
|
— |
Vendor references (7)
References embedded in the original CVE record by the assigning CNA.
- GitHub Security Advisory (GHSA-g4mf-q5hw-f9j9) vendor-advisory
- https://github.com/orval-labs/orval/pull/4006 patchissue-tracking
- https://github.com/orval-labs/orval/commit/155a5b7a38ff6886020cbc4c292db57c2793e6b6 patch
- https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23 patch
- https://github.com/orval-labs/orval/blob/v8.28.1/packages/hono/src/index.ts#L169-L175 technical-description
- https://github.com/orval-labs/orval product
- VulnCheck Advisory: orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path third-party-advisory
Web references (0)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
No web references attached yet.
NVD-tagged references (7)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://github.com/orval-labs/orval disclosure@vulncheck.com
- https://github.com/orval-labs/orval/blob/v8.28.1/packages/hono/src/index.ts#L169-L175 disclosure@vulncheck.com
- https://github.com/orval-labs/orval/commit/155a5b7a38ff6886020cbc4c292db57c2793e6b6 disclosure@vulncheck.com
- https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23 disclosure@vulncheck.com
- https://github.com/orval-labs/orval/pull/4006 disclosure@vulncheck.com
- https://github.com/orval-labs/orval/security/advisories/GHSA-g4mf-q5hw-f9j9 disclosure@vulncheck.com
- https://www.vulncheck.com/advisories/orval-orval-hono-before-8.29.0-code-injection-via-openapi-path disclosure@vulncheck.com
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-96754.json.
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:npm/orval",
"product": "orval",
"vendor": "orval-labs",
"versions": [
{
"lessThan": "8.29.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8.29.0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:orval:orval:*:*:*:*:*:*:*:*",
"versionEndExcluding": "8.29.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Enrik Mustafa"
}
],
"datePublic": "2026-09-06T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a static path segment to inject arbitrary JavaScript code that executes when the generated TypeScript module is imported."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-94",
"description": "Improper Control of Generation of Code ('Code Injection')",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T16:23:51.012Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-g4mf-q5hw-f9j9)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/orval-labs/orval/security/advisories/GHSA-g4mf-q5hw-f9j9"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/orval-labs/orval/pull/4006"
},
{
"tags": [
"patch"
],
"url": "https://github.com/orval-labs/orval/commit/155a5b7a38ff6886020cbc4c292db57c2793e6b6"
},
{
"tags": [
"patch"
],
"url": "https://github.com/orval-labs/orval/commit/d346d94a660e50a2f8d0f7c17fee2c4c69d8dc23"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/orval-labs/orval/blob/v8.28.1/packages/hono/src/index.ts#L169-L175"
},
{
"tags": [
"product"
],
"url": "https://github.com/orval-labs/orval"
},
{
"name": "VulnCheck Advisory: orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/orval-orval-hono-before-8.29.0-code-injection-via-openapi-path"
}
],
"title": "orval @orval/hono before 8.29.0 Code Injection via OpenAPI Path",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-96754",
"datePublished": "2026-09-23T16:23:51.012Z",
"dateReserved": "2026-09-23T15:58:24.561Z",
"dateUpdated": "2026-09-23T16:23:51.012Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}