External risk intelligence

Orval Factory Generator Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-96756

Orval is a build-time development tool used to generate code from OpenAPI schemas. It operates in developer environments, CI/CD pipelines, or build systems, not as an internet-facing service or production runtime component. Consequently, the vulnerable component is not exposed to the public internet.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A code injection vulnerability exists in a development tool that generates code from API specifications. This flaw could allow attackers to execute arbitrary code within the environment where the code generation occurs, if specific configurations are enabled. The primary concern is to determine if this development tool is used within our organization and, if so, to assess the potential exposure.

  • Code can be injected during code generation.
  • Affects developer tools, not production systems.
  • Confirm relevance and understand potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could inject malicious code by providing specially crafted default values within an OpenAPI schema. This occurs when the factory generator, with specific options enabled, fails to properly escape these values when creating new `Date` objects. The attacker's injected code could then be executed with the privileges of the process running the generator.

  • Entry condition: Unauthenticated network access.
  • Trigger point: Code generation with specific options.
  • Resulting risk: Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary code within the process consuming the generated factory code, when specific configuration options are enabled. This could affect the integrity of the build or development environment.

  • Code execution in consumer process.
  • Via crafted OpenAPI schema defaults.
  • Compromise of development environment.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts the `@orval/core` factory generator, specifically concerning how default date values are handled. Ownership likely falls to development teams responsible for code generation pipelines and build processes, potentially in coordination with platform or security teams overseeing developer tooling. The initial step involves identifying all instances where `@orval/core` is utilized for code generation, assessing the criticality of these generation tasks, and confirming the presence of the vulnerable component within development or build environments.

  • Development or platform teams should own.
  • Verify code generation pipeline usage.
  • Plan staged remediation to development environments.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Orval and how is it used?

Orval is an open-source development tool that automates API integration by generating client code directly from OpenAPI specifications. Developers use it to save time by auto-creating TypeScript services, type definitions, and mock functions instead of writing them by hand. It serves as a bridge between API contracts and application code, typically running locally on a developer's machine or within automated build pipelines.

What does the code injection vulnerability in CVE-2026-96756 mean?

The vulnerability is classified as Improper Control of Generation of Code (CWE-94). It happens because the tool's factory generator does not safely sanitize input when processing date default values. If an OpenAPI schema contains a specifically crafted apostrophe in a date field, the generator can treat it as part of the system command rather than just text, causing the process to execute unintended instructions.

How can an attacker trigger this vulnerability?

An attacker needs to supply a malicious OpenAPI schema containing a crafted date default value to the Orval generator. The bug only triggers if you are using specific configurations, namely the 'factoryMethods' and 'useDates' options. If these features are disabled, or if you are using a sanitized schema without malicious date-related inputs, the flaw does not activate.

Is my production system at risk from this CVE?

According to Halo Surface Signal, it is very unlikely. Orval is a build-time development utility, not a production runtime service or an internet-facing component. The risk is contained within developer machines, CI/CD pipelines, or build environments, meaning it is not directly reachable by attackers over the public internet.

How do I respond to this vulnerability?

Start by identifying all projects or build pipelines that rely on the @orval/core package. Verify which projects have 'factoryMethods' and 'useDates' enabled, as these are the necessary conditions for the bug. The primary resolution is to update the @orval/core library to version 8.30.0 or higher, which includes the necessary security fixes for sanitizing date values during code generation.

References