orval
npm12 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting orvalpage 1 of 1
- CVE-2026-62680HIGHCVSS 7.1EG 7.1✓ Fixed in 8.22.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. Pro…
- CVE-2026-62681CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch, r…
- CVE-2026-62682CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into request URL template literals generated when output.baseUrl.…
- CVE-2026-71864CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header parameter name is emitted into the generated request-validation zod.object({...}) schema …
- CVE-2026-71865CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a query parameter name is emitted into the generated request-validation zod.object({...}) schema w…
- CVE-2026-71866CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema property name is emitted into the generated zod.object({...}) schema wit…
- CVE-2026-71867CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories w…
- CVE-2026-71868CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-level template literal emitted by zod sc…
- CVE-2026-71869CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template literal emitted by …
- CVE-2026-71871CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into a module-level template literal emitte…
- CVE-2026-72716CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query parameter default is emitted into a module-level template literal emitted…
- CVE-2026-72717CRITICALCVSS 9.3EG 9.3✓ Fixed in 8.21.02026-08-19
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template literal emitted by zod s…
Check whether orval is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for orval CVEs against the assets you own.
Start Free Scan →