NONE · 0

CVE-2026-71867

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object...

Vulnerability Description

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated mock factory is called by tests or an MSW handler, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/core/src/getters/keys.ts function getKey and MSW mock generation. This issue is fixed in version 8.21.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-71867?

CVE-2026-71867 is a documented vulnerability. Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object...

How severe is CVE-2026-71867?

CVSS scoring is not yet available for CVE-2026-71867. Check NVD for updates.

Is there a patch for CVE-2026-71867?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.