External risk intelligence

Orval Code Injection via Unescaped OpenAPI Media Type.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-96757

Orval is a development-time tool used to generate code from OpenAPI specifications. The vulnerability exists within the generated build artifacts or development workflow, not in a live, internet-facing service or appliance. As a build-time dependency, it lacks direct exposure to the public internet in standard production deployments.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a vulnerability in code generation tools that could allow attackers to inject malicious JavaScript through specially crafted specifications. This could lead to the execution of unintended code when the generated code is used in operations or mock resolvers, impacting the integrity of development workflows. The main concern is confirming relevance and exposure to our development processes.

  • Code generation tool flaw.
  • Impacts development, not live services.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could inject malicious JavaScript into a project by crafting a specially designed OpenAPI specification. This malicious code would execute when the generated code, used for fetching data or in mock resolvers, is invoked during the development or build process. The risk arises from the failure to properly escape certain keys within the OpenAPI specification, leading to script execution within the development environment.

  • Entry condition: Malicious OpenAPI specification.
  • Trigger point: Invoked generated code.
  • Resulting risk: JavaScript execution in development.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow for the injection of JavaScript into generated code when a specially crafted OpenAPI specification is processed. This script could then execute when the generated code is used for operations like fetching data or resolving mock data, potentially impacting the behavior of these generated functions when supported by the advisory.

  • Generated code
  • Malicious OpenAPI input
  • Compromised service behavior

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts Orval, a tool used in development workflows for generating code from OpenAPI specifications. Teams responsible for build pipelines, CI/CD, and application development should investigate its presence in their environments. The first step is to identify all instances of Orval used in code generation, confirm if the generated artifacts are distributed or used in sensitive environments, and then assign ownership for remediation based on risk.

  • Application development and platform teams own this issue.
  • Verify Orval's use in code generation pipelines.
  • Mitigate by updating Orval or sanitizing generated code.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Orval and how is it used in development?

Orval is a software development tool that automates the creation of client code directly from OpenAPI specifications. Developers use it to speed up the process of generating fetch functions and mock data resolvers, ensuring their application code aligns with API definitions. It acts as a build-time dependency that translates formal API descriptions into functional code modules.

What does CVE-2026-96757 mean for code safety?

This vulnerability is classified as CWE-94, or Improper Control of Generation of Code. In Orval versions before 8.29.0, the tool fails to properly sanitize media-type keys when writing them into generated code. If an attacker provides a malicious OpenAPI specification, they can inject JavaScript that runs automatically when the generated fetch operations or mock resolvers are executed.

How can an attacker trigger this code injection?

The trigger requires the use of a specially crafted OpenAPI specification containing malicious media-type keys. If the specification is clean, the bug is not triggered. The vulnerability activates only when Orval processes the tainted input and the resulting generated code is subsequently invoked within a build or development environment.

Is my environment at risk from this vulnerability?

According to Halo Surface Signal, this is unlikely because Orval is a development-time tool rather than a live, internet-facing service. Because it operates within build pipelines or local development workflows, it lacks direct exposure to the public internet. The primary concern is protecting your internal development processes and build artifacts from potentially malicious input.

How should I respond if I use Orval?

First, identify all projects or build pipelines that rely on Orval to generate code. Once mapped, update Orval to version 8.29.0 or later to receive the fix. Platform and development teams should review their OpenAPI sources to ensure they come from trusted origins, as the vulnerability relies on the ingestion of specifically crafted input files.

References