CVE-2026-25141
Last modified
CVE-2026-25141 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7.21.0 and 8.2.0 have an incomplete fix for CVE-2026-23947. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7.21.0 and 8.2.0 have an incomplete fix for CVE-2026-23947. While the jsStringEscape function properly handles single quotes ('), double quotes (") and so on, it is still possible to achieve code injection using only a limited set of characters that are currently not escaped. The vulnerability lies in the fact that the application can be forced to execute arbitrary JavaScript using characters such as []()!+. By using a technique known as JSFuck, an attacker can bypass the current sanitization logic and run arbitrary code without needing any alphanumeric characters or quotes. Version 7.21.0 and 8.2.0 contain an updated fix.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Orval | Orval | >= 7.19.0, < 7.21.0 |
| Orval | Orval | >= 8.0.0, < 8.2.0 |
References
- https://github.com/orval-labs/orval/releases/tag/v7.21.0Product, Release Notes
- https://github.com/orval-labs/orval/releases/tag/v8.2.0Product, Release Notes
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-25141?
How severe is CVE-2026-25141?
How do I fix CVE-2026-25141?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-25136Rucio is a software framework that provides functionality to…6.1
- CVE-2026-25137The NixOs Odoo package is an open source ERP and CRM system.…9.1
- CVE-2026-25138Rucio is a software framework that provides functionality to…5.3
- CVE-2026-25139RIOT is an open-source microcontroller operating system, des…9.1
- CVE-2026-2514In Progress Flowmon ADS versions prior to 12.5.5 and 13.0.3,…8.6
- CVE-2026-25140apko allows users to build and publish OCI container images …7.5
- CVE-2026-25142SandboxJS is a JavaScript sandboxing library. Prior to 0.8.2…10
- CVE-2026-25143melange allows users to build apk packages using declarative…7.8
- CVE-2026-25144Talishar is a fan-made Flesh and Blood project. A Stored XSS…5.3
- CVE-2026-25145melange allows users to build apk packages using declarative…5.5
- CVE-2026-25146OpenEMR is a free and open source electronic health records …8.1
- CVE-2026-25147OpenEMR is a free and open source electronic health records …7.1
Are you affected by CVE-2026-25141?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
