External risk intelligence

Orval operationId Code Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-96759

Orval is a build-time development tool used to generate code from OpenAPI specifications. Vulnerabilities in such tools occur during the software development lifecycle, not in production runtime environments. There is no typical public internet exposure for this build-time utility.

Code Injection

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in a development tool that generates code from API specifications. The flaw allows attackers to inject malicious JavaScript code that could execute when the generated code is used. While the tool itself is not typically exposed to the internet in production, its use in the development pipeline could have implications if the generated code is not properly secured.

  • Code generation tool can be tricked.
  • Developers should check their code creation.
  • Confirm relevance and exposure in development.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by crafting a malicious OpenAPI specification with a specially designed `operationId`. When the generated code, which includes TanStack Query mutator options, is used, this crafted `operationId` would execute arbitrary JavaScript within the application, potentially leading to a complete compromise.

  • Entry condition: Malicious OpenAPI specification.
  • Trigger point: Application uses generated code.
  • Resulting risk: Arbitrary JavaScript execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to inject arbitrary JavaScript code into generated TanStack Query mutator options metadata when using a crafted `operationId` in an OpenAPI specification. This code may execute when the generated hooks are called in a supported environment.

  • Generated metadata objects.
  • JavaScript code injection via `operationId`.
  • Arbitrary code execution in supported environments.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability affects the Orval code generation tool. Teams responsible for the software development lifecycle, particularly those managing build pipelines and code generation from OpenAPI specifications, should investigate. The first practical step is to identify where Orval is used in the development process, confirm if the generated code is deployed to production, and then determine the scope of impact and the appropriate remediation.

  • Identify Orval usage in development pipelines.
  • Verify if generated code reaches production.
  • Plan remediation based on identified risks.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Orval?

Orval is a specialized developer tool designed to automate the creation of TypeScript clients from OpenAPI specifications. It is primarily used during the software development lifecycle to generate boilerplate code for interacting with APIs, such as TanStack Query hooks, saving developers from writing repetitive network request logic manually.

How does CVE-2026-96759 allow code injection?

This vulnerability is classified as Improper Control of Generation of Code, specifically CWE-94. The tool fails to sanitize the 'operationId' field found in OpenAPI files. If an attacker provides a malicious 'operationId' containing JavaScript, Orval inadvertently embeds that code into the generated application files, where it runs whenever the affected API hooks are subsequently called.

What triggers this code injection?

The flaw is triggered only when Orval processes a crafted OpenAPI specification containing a malicious 'operationId'. Simply having the tool installed does not trigger the bug; the malicious input must be present during the code generation process. If your OpenAPI files contain only standard, trusted identifiers, the generated output will not include the injected code.

Is my application at risk from this CVE?

According to Halo Surface Signal, this risk is considered very unlikely for public-facing systems. Because Orval is a build-time utility, the vulnerability occurs within your private development pipeline, not in a running production server. However, you remain at risk if an attacker compromises your source files or influences the OpenAPI documents used to build your application code.

How should I respond to this vulnerability?

Begin by auditing your development pipelines to identify where Orval is used to generate code. Update your Orval version to 8.29.0 or later, which resolves the escaping issue. Once updated, re-generate your API hooks to ensure the malicious injection path is removed from your codebase and verify that all generated code currently in production was created using the patched version.

References