VulnSea

orval-labs has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 9.8 (critical), with 5 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-94 (6).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.8
Publish → KEV
Last 90 days
6 prev 0

Weakness classes

Products

  • orval 6
6
Total CVEs
5
Critical
0
CISA KEV
0
Exploited

orval-labs vulnerabilities

CVEs affecting orval-labs, newest first. Open any entry for full detail, references, and exploit status.

6 CVEsRSS

CVE-2026-96759Critical· 9.8
today

orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects

orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript code through a crafted operationId in an OpenAPI spe…

Midnightorval-labs · orvalvia NVD
CVE-2026-96758Critical· 9.8PoC
today

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema…

Abyssalorval-labs · orvalvia NVD
CVE-2026-96757Critical· 9.8PoC
today

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code

orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications t…

Abyssalorval-labs · orvalvia NVD
CVE-2026-96756High· 8.1
today

orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls

orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to escape date default values in new Date() calls. Attackers can inject arbitrary expressions through apostrophes in Open…

Twilightorval-labs · orvalvia NVD
CVE-2026-96755Critical· 9.8
today

orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals

orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts OpenAPI schema defaults into template literals. Attackers can inject arbitrary JavaScript expressions via schema def…

Midnightorval-labs · orvalvia NVD
CVE-2026-96754Critical· 9.8
today

orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals

orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape OpenAPI path values in single-quoted route literals. Attackers can craft an OpenAPI document with an apostrophe in a st…

Midnightorval-labs · orvalvia NVD
orval-labs vulnerabilities (CVEs) · VulnSea