OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-96756

HIGH · CVSS 8.1 EPSS 0.48% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Versions of orval prior to 8.30.0 are vulnerable to a code injection flaw in the @orval/core factory generator, which fails to properly escape date default values in new Date() calls. This allows attackers to inject arbitrary expressions via apostrophes in OpenAPI schema defaults, potentially executing code with the privileges of the consumer process when factoryMethods and useDates options are enabled. Organizations using orval should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96756
Severity
HIGH
CVSS
8.1
EPSS
0.48%

Original NVD Description

orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in OpenAPI schema defaults to execute code with the privileges of the consumer process when factoryMethods and useDates options are enabled.