CVE Explorer
CVE-2026-25141
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7.21.0 and 8.2.0 have an incomplete fix for CVE-2026-23947. While the jsStringEscape function properly handles single quotes ('), double quotes (") and so on, it is still possible to achieve code injection using only a limited set of characters that are currently not escaped. The vulnerability lies in the fact that the application can be forced to ex
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"orval","vendor":"orval-labs","versions":[{"status":"affected","version":">= 7.19.0, < 7.21.0"},{"status":"affected","version":">= 8.0.0, < 8.2.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:83eeffc5da1805b04aeba0bc8ae0498c7b6c1c887089f2e849f449aab10747d6 · sha256:cbf2d9bbad00cf74… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:83eeffc5da1805b04aeba0bc8ae0498c7b6c1c887089f2e849f449aab10747d6 · sha256:cbf2d9bbad00cf74… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-94","description":"CWE-94: Improper Control of Generation of Code ('Code Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:83eeffc5da1805b04aeba0bc8ae0498c7b6c1c887089f2e849f449aab10747d6 · sha256:cbf2d9bbad00cf74… · /containers/cna/problemTypes/0/descriptions/0
Source references
5 source assertions{"name":"https://github.com/orval-labs/orval/blob/02211fc413524be340ba9ace866a2ef68845ca7c/packages/core/src/utils/string.ts#L227","tags":["x_refsource_MISC"],"url":"https://github.com/orval-labs/orval/blob/02211fc413524be340ba9ace866a2ef68845ca7c/packages/core/src/utils/string.ts#L227"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:83eeffc5da1805b04aeba0bc8ae0498c7b6c1c887089f2e849f449aab10747d6 · sha256:cbf2d9bbad00cf74… · /containers/cna/references/2
{"name":"https://github.com/orval-labs/orval/releases/tag/v7.21.0","tags":["x_refsource_MISC"],"url":"https://github.com/orval-labs/orval/releases/tag/v7.21.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:83eeffc5da1805b04aeba0bc8ae0498c7b6c1c887089f2e849f449aab10747d6 · sha256:cbf2d9bbad00cf74… · /containers/cna/references/3
{"name":"https://github.com/orval-labs/orval/releases/tag/v8.2.0","tags":["x_refsource_MISC"],"url":"https://github.com/orval-labs/orval/releases/tag/v8.2.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:83eeffc5da1805b04aeba0bc8ae0498c7b6c1c887089f2e849f449aab10747d6 · sha256:cbf2d9bbad00cf74… · /containers/cna/references/4
{"name":"https://github.com/orval-labs/orval/security/advisories/GHSA-gch2-phqh-fg9q","tags":["x_refsource_CONFIRM"],"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-gch2-phqh-fg9q"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:83eeffc5da1805b04aeba0bc8ae0498c7b6c1c887089f2e849f449aab10747d6 · sha256:cbf2d9bbad00cf74… · /containers/cna/references/0
{"name":"https://github.com/orval-labs/orval/security/advisories/GHSA-h526-wf6g-67jv","tags":["x_refsource_MISC"],"url":"https://github.com/orval-labs/orval/security/advisories/GHSA-h526-wf6g-67jv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:83eeffc5da1805b04aeba0bc8ae0498c7b6c1c887089f2e849f449aab10747d6 · sha256:cbf2d9bbad00cf74… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.