Aller au contenu

Fiche vulnérabilité

CVE-2026-22785 : faille critique orval orval (CVSS 9.8)

Description

orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation logic relies on string manipulation that incorporates the summary field from the OpenAPI specification without proper validation or escaping. This allows an attacker to "break out" of the string literal and inject arbitrary code. This vulnerability is fixed in 7.18.0.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
12 janv. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • orval orval

Références

Rechercher une autre vulnérabilité dans la base CVE