Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

orval — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in orval, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the open-source code generation tool orval. It collects security weaknesses related to code generation, API client generation, and dependency handling, covering advisories published over the past several years. Here you can track orval security advisories, understand common weakness classes in code generation tools, and review the vulnerability history for this product.

Vendor: orval-labs

CVE ID Title CVSS Severity Published
CVE-2026-62680 Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref CWE-22 7.1 High 2026-08-19
CVE-2026-62682 Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification) CWE-94 9.3 Critical 2026-08-19
CVE-2026-72717 Orval: Import-time RCE via schema default -> zod module-level template literal CWE-94 9.3 Critical 2026-08-19
CVE-2026-71867 Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator CWE-89 9.3 Critical 2026-08-19
CVE-2026-71868 Orval: Import-time RCE via enum-typed default -> zod module-level template literal CWE-94 9.3 Critical 2026-08-19
CVE-2026-71865 Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli CWE-94 9.3 Critical 2026-08-19
CVE-2026-71869 Orval: Import-time RCE via array-items default -> zod module-level template literal CWE-94 9.3 Critical 2026-08-19
CVE-2026-71864 Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client CWE-94 9.3 Critical 2026-08-19
CVE-2026-71871 Orval: Import-time RCE via header-parameter default -> zod module-level template literal CWE-94 9.3 Critical 2026-08-19
CVE-2026-72716 Orval: Import-time RCE via query-parameter default -> zod module-level template literal CWE-1336 9.3 Critical 2026-08-19
CVE-2026-62681 Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) CWE-94 9.3 Critical 2026-08-19
CVE-2026-71866 Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client CWE-89 9.3 Critical 2026-08-19
CVE-2026-25141 Orval has a code injection via unsanitized x-enum-descriptions uing JS comments CWE-94 8.6AI High AI 2026-01-30
CVE-2026-24132 Orval Mock Generation Code Injection via const CWE-77 8.1 - 2026-01-22
CVE-2026-23947 Orval MCP client is vulnerable to code injection via unsanitized x-enum-descriptions in enum generation CWE-77 10.0AI Critical AI 2026-01-20
CVE-2026-22785 orval MCP client is vulnerable to a code injection attack. CWE-77 8.2AI High AI 2026-01-12

All 16 known CVE vulnerabilities affecting orval with full Chinese analysis, references, and POCs where available.