External risk intelligence

Orval Core Code Injection via Form Data Serialization.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-96758

The vulnerability exists in a build-time development tool used for code generation. It is not part of a deployed application's runtime attack surface, as it affects the generated client code during the development or CI/CD build process rather than being an internet-facing component of a deployed service.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a code injection vulnerability identified in a development tool that generates client code from OpenAPI schemas. The flaw allows specially crafted schema property names to execute arbitrary code with consumer process privileges during the client build, potentially impacting the integrity of the generated code. The main concern is confirming relevance and exposure to our development workflows.

  • Vulnerability allows code injection during client code generation.
  • Affects developer tools, not deployed applications directly.
  • Confirm if this tool is used in our development process.

Attack Path

How an attacker could exploit the issue

Attackers could inject malicious code into the property names of form data. This occurs when the code generation tool processes OpenAPI schema definitions and fails to properly escape special characters in property names. If these names are later used in a client application that builds form data, the injected code can execute with the privileges of the application that consumes the data.

  • No specific user interaction needed.
  • Vulnerability triggered by code generation process.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow attackers to inject code into generated client applications. This code could execute with the privileges of the consumer process when the client builds FormData bodies, potentially affecting service behavior.

  • Executed code with consumer privileges.
  • Code injection via form-data serialization.
  • Compromise of consumer process.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects the form-data serializer in the @orval/core tool, which is used during the development or CI/CD build process. Ownership will likely fall to development teams or platform engineers responsible for the build tooling and generated client code. The first practical step is to confirm the specific usage and scope of @orval/core within the development lifecycle, identify which projects generate client code, and assess the risk associated with any affected property names.

  • Development or platform teams own resolution.
  • Verify @orval/core build-time usage.
  • Plan code generation updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is @orval/core and how is it used?

Orval is a build-time utility designed to automate the creation of TypeScript clients from OpenAPI specifications. Developers integrate it into their build or CI/CD pipelines to generate standardized API client code, which helps ensure the client remains synchronized with the backend service definitions. It acts as an intermediary tool that transforms documentation into functional source code.

What does the code injection vulnerability in CVE-2026-96758 mean?

This is a CWE-94 weakness, which involves the improper neutralization of special elements used in a command or code. Specifically, the tool fails to escape multipart property names, allowing malicious syntax like ${...} to be inserted into the generated source. When the resulting client processes these names, it treats them as active template literals rather than static strings, leading to unintended code execution.

How is this vulnerability triggered in the generation process?

The flaw is triggered when the tool parses an OpenAPI schema containing specifically crafted property names. It is not triggered by standard API traffic or runtime interactions with a deployed application. If the property names are benign, the generated code remains safe; the risk only manifests when the input schema includes malicious expressions that the serializer fails to sanitize before embedding them into the template.

Do I need to worry if my application is internet-facing?

According to Halo Surface Signal, this vulnerability is categorized as very unlikely to be an immediate runtime threat because it resides in a build-time tool. While the resulting client code could theoretically be problematic, the injection itself occurs during the developer's build process rather than being an internet-facing component that an external attacker can directly target via a web request.

What should I do if I use @orval/core?

Begin by auditing your development projects to identify where @orval/core is implemented in your pipelines. Check your current version against the patched release mentioned in the advisory and plan to update your tooling accordingly. Since this involves the generation of source code, verify the integrity of your current client outputs and confirm that your OpenAPI schemas are sourced from trusted locations.

References