CyberRota Analysis
AI-GeneratedVersions 8.14.0 through 8.28.1 of the Orval library for Java are vulnerable to a critical code injection flaw that allows attackers to execute arbitrary JavaScript expressions through manipulated OpenAPI schema defaults. This vulnerability poses a significant risk as it can lead to unauthorized code execution within the application. Developers and organizations using these specific versions of Orval should prioritize immediate remediation to mitigate potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema defaults containing ${...} syntax, which are executed at module scope when the generated code is built or imported.