SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-62681

CRITICAL · CVSS 9.3 EPSS 0.66% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability affects Orval, a tool that generates JavaScript clients from OpenAPI specifications, allowing unescaped backticks in request URL templates to lead to code execution in various environments, including developer and CI settings. This critical flaw could enable attackers to execute arbitrary JavaScript, posing significant risks to application security. Organizations utilizing Orval versions prior to 8.21.0 should prioritize upgrading to the latest version to mitigate this severe risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-62681
Severity
CRITICAL
CVSS
9.3
EPSS
0.66%
Java

Original NVD Description

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch, react-query, and SWR clients without safe encoding. This permits attacker-controlled JavaScript to be evaluated when a generated request, URL-builder, or query-key function is called, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/core/src/getters/route.ts and route generation consumers. This issue is fixed in version 8.21.0.