OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-96758

CRITICAL · CVSS 9.8 EPSS 0.54% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A code injection vulnerability in the form-data serializer of orval @orval/core versions prior to 8.28.0 allows attackers to inject malicious expressions into OpenAPI schema property names, leading to potential execution of arbitrary code during client builds. This critical flaw can compromise the integrity of applications that utilize this library, particularly when generating FormData bodies with consumer process privileges. Developers and organizations using orval should prioritize updating to version 8.28.0 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-96758
Severity
CRITICAL
CVSS
9.8
EPSS
0.54%

Original NVD Description

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live interpolation when the generated client builds FormData bodies with consumer process privileges.