External risk intelligence

Orval Code Injection via Schema Defaults

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-96755

Orval is a developer tool used for generating code from OpenAPI schemas during the build process. The vulnerability exists within a generator component used by developers, not in a running service or production application. It is executed in local or build-time environments, not on public-facing internet infrastructure.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A code injection vulnerability has been identified in the orval library, specifically within the `@orval/effect` generator. This issue allows for arbitrary JavaScript execution during the code generation process, which could have implications for software development workflows. The main concern is confirming the relevance and exposure of this tool within your development environments.

  • Arbitrary code can run during development builds.
  • Critical flaw impacts code generation tools.
  • Confirm if this developer tool is in use.

Attack Path

How an attacker could exploit the issue

An attacker could leverage a code injection flaw within the Orval tool's OpenAPI schema conversion process. By supplying specially crafted schema defaults, an attacker could introduce malicious JavaScript code that gets executed when the generated code is processed. This could occur during a development build or when the code is imported into a project.

  • Attacker must control schema defaults.
  • Code executed during build or import.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

The `@orval/effect` generator in Orval could allow an attacker to inject arbitrary JavaScript code through OpenAPI schema defaults. This code would execute when the generated code is built or imported, potentially impacting the integrity of the build process.

  • Build process code integrity at risk.
  • Arbitrary JavaScript injected via schema defaults.
  • Build process compromise is possible.

Operational Fix

Recommended remediation, mitigation, and detection steps

The @orval/effect generator is used in development and build pipelines, indicating that development teams and platform engineers are the primary stakeholders for this vulnerability. The first practical step is to identify where this tool is utilized in the CI/CD process and during local development, assess the risk associated with code injection during these phases, and then coordinate with the development team for remediation.

  • Development teams should own the remediation.
  • Verify usage in build and local environments.
  • Plan updates during the next maintenance window.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Orval and how is it used?

Orval is a developer utility designed to generate TypeScript code and API clients from OpenAPI schemas. It helps teams automate the creation of data-fetching layers in applications, ensuring that client-side code stays synchronized with backend API definitions during the software development lifecycle.

What is the nature of the vulnerability in CVE-2026-96755?

This vulnerability is a form of code injection known as CWE-94. It occurs because the @orval/effect generator incorrectly handles template literals when processing OpenAPI schema defaults. If a schema contains specific syntax, the tool can be tricked into executing unintended JavaScript commands when the generated files are built or imported into a project.

How does an attacker trigger this code injection?

An attacker triggers the bug by providing a malicious OpenAPI schema where the default values include specific ${...} syntax. The vulnerability does not trigger if your schemas do not contain these specific default values or if you are not using the affected @orval/effect generator component to process those definitions.

Do I need to worry about this if my site is not internet-facing?

According to Halo Surface Signal, this vulnerability is very unlikely to be a direct internet-facing threat. Because Orval is a build-time developer tool, the risk centers on your internal development environments and CI/CD pipelines rather than public infrastructure. The primary concern is protecting your build integrity rather than securing live network traffic.

How should I respond if my team uses Orval?

First, identify every project in your environment that utilizes the @orval/effect generator. Confirm whether these projects are currently using any of the affected versions. Coordinate with your development team to audit schema defaults and plan for an update to a secure version of the library during your next scheduled maintenance window.

References