External risk intelligence

Orval Hono Generator Code Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-96754

This vulnerability affects a code generation tool used during the build-time development process. It is not a component of a deployed application or service, but rather a development-time dependency that runs locally or in CI/CD pipelines to generate source code. It lacks any public-internet-facing presence in common production deployments.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in the @orval/hono generator tool that can allow for code injection if a specially crafted OpenAPI document is used. This could potentially lead to the execution of arbitrary JavaScript code when the generated TypeScript module is imported, impacting the development process by compromising the integrity of generated code.

  • Code can be injected via OpenAPI path values.
  • Affects code generation tools, not deployed applications.
  • Confirm if this development tool is used internally.

Attack Path

How an attacker could exploit the issue

An attacker can inject arbitrary JavaScript code by providing a crafted OpenAPI document to the `@orval/hono` generator. This code executes when the generated TypeScript module is imported, leading to a complete compromise of systems that process these generated files.

  • Entry condition: Craft an OpenAPI document.
  • Trigger point: Import generated TypeScript module.
  • Resulting risk: Arbitrary JavaScript code execution.

Live Threat

Current exploitation, exposure, and threat context

A code injection vulnerability in the @orval/hono generator could allow attackers to execute arbitrary JavaScript code. This occurs when an OpenAPI document contains an apostrophe in a static path segment, which is then improperly escaped in generated TypeScript modules. The malicious code executes when the generated module is imported.

  • Generated code and build processes.
  • Malicious JavaScript injected via OpenAPI path.
  • Compromised build environment or downstream code.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability exists in a code generation tool used during development. The first step is to confirm if this tool is used in your build or CI/CD pipelines, identify the teams responsible for managing development dependencies, and then assess the risk if the generated code is deployed.

  • Identify development tool ownership.
  • Verify usage in build/CI/CD pipelines.
  • Plan code updates based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Orval and the @orval/hono generator?

Orval is a tool used by developers to automatically generate TypeScript code from OpenAPI specifications. The @orval/hono generator is a specific component within this ecosystem designed to produce boilerplate for Hono, a lightweight web framework. By automating the creation of route handlers and data types, it helps maintain consistency between an API definition and the application code.

What does code injection mean for CVE-2026-96754?

This vulnerability is classified as Improper Control of Generation of Code (CWE-94). It occurs because the tool does not properly handle apostrophes within OpenAPI path definitions. When the tool generates a TypeScript file, it treats these characters as code rather than text, effectively allowing an attacker to inject custom JavaScript that runs whenever that generated file is imported or used.

How is this code injection vulnerability triggered?

The flaw is triggered when the generator processes a malicious or malformed OpenAPI document containing an apostrophe in a static path segment. If the path does not contain such special characters, the generator functions normally. Importantly, the vulnerability does not trigger while simply running the generator; the malicious code only executes later when the generated TypeScript module is imported into an application.

Is this vulnerability relevant to my production services?

According to Halo Surface Signal, this risk is very unlikely to affect production services directly. Because this is a build-time development tool, it typically operates within local developer environments or CI/CD pipelines rather than as a component of a deployed, internet-facing application. Your primary concern is whether your build processes rely on vulnerable versions of this specific generator.

How do I respond to CVE-2026-96754 in my environment?

Begin by auditing your dependency manifests to see if you are using versions of @orval/hono older than 8.29.0. If you find the tool in your build pipelines, communicate with your development teams to determine if they process untrusted or external OpenAPI files. Once identified, update the dependency to a patched version to ensure the generated TypeScript code remains secure and free from injected logic.

References