Orval MCP client is vulnerable to code injection via unsanitized x-enum-descriptions in enum generation
Published Jan 20, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.84%
Description
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vulnerable to arbitrary code execution in environments consuming generated clients. This issue is similar in nature to CVE-2026-22785, but affects a different code path in @orval/core that was not addressed by CVE-2026-22785's fix. The vulnerability allows untrusted OpenAPI specifications to inject arbitrary TypeScript/JavaScript code into generated clients via the x-enumDescriptions field, which is embedded without proper escaping in getEnumImplementation(). I have confirmed that the injection occurs during const enum generation and results in executable code within the generated schema files. Orval 7.19.0 and 8.0.2 contain a fix for the issue.
Affected products
-
- Version < 7.19.0StatusaffectedConstraints-
- Version >= 8.0.0-rc.0, < 8.0.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Orval-Labs | Orval | n/a |
|
No data.
No Red Hat product state for this CVE.
@orval/core
npm
Introduced 8.0.0-rc.0 Fixed 8.0.2@orval/core
npm
Introduced 0 Fixed 7.19.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @orval/core | 8.0.0-rc.0 | 8.0.2 |
| npm | @orval/core | 0 | 7.19.0 |
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-3590 Advisory
- https://github.com/advisories/GHSA-h526-wf6g-67jv Advisory
- https://github.com/orval-labs/orval/commit/9e5d93533904936678ba93b5d20f6bca176a4e1e
- https://github.com/orval-labs/orval/releases/tag/v7.19.0
- https://github.com/orval-labs/orval/releases/tag/v8.0.2 x_refsource_MISCProductRelease Notes
- https://github.com/orval-labs/orval/security/advisories/GHSA-h526-wf6g-67jv x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-23947
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-3590 | Advisory | |
| https://github.com/advisories/GHSA-h526-wf6g-67jv | Advisory | |
| https://github.com/orval-labs/orval/commit/9e5d93533904936678ba93b5d20f6bca176a4e1e | ||
| https://github.com/orval-labs/orval/releases/tag/v7.19.0 | ||
| https://github.com/orval-labs/orval/releases/tag/v8.0.2 | x_refsource_MISCProductRelease Notes | |
| https://github.com/orval-labs/orval/security/advisories/GHSA-h526-wf6g-67jv | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-23947 |
Change history (0)
No recorded changes yet.