CVE-2026-62681
Last modified
CVE-2026-62681 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch, react-query, and SWR clients without safe encoding. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch, react-query, and SWR clients without safe encoding. This permits attacker-controlled JavaScript to be evaluated when a generated request, URL-builder, or query-key function is called, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/core/src/getters/route.ts and route generation consumers. This issue is fixed in version 8.21.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| orval-labs | orval | < 8.21.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-62681?
How severe is CVE-2026-62681?
How do I fix CVE-2026-62681?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-62674Omnigent is an open-source AI agent framework and meta-harne…9
- CVE-2026-62675Omnigent is an open-source AI agent framework and meta-harne…8.8
- CVE-2026-62676Omnigent is an open-source AI agent framework and meta-harne…7.1
- CVE-2026-62677Omnigent is an open-source AI agent framework and meta-harne…8.8
- CVE-2026-6268The EventPress WordPress theme before 22.2 does not sanitize…7.1
- CVE-2026-62680Orval generates type-safe JavaScript clients in TypeScript f…7.1
- CVE-2026-62682Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-62683File Browser is a file managing interface for uploading, del…3.1
- CVE-2026-62684File Browser is a file managing interface for uploading, del…2.7
- CVE-2026-62685File Browser is a file managing interface for uploading, del…8.1
- CVE-2026-62688Heap-based buffer overflow in Windows MIDI Service Module al…7.8
- CVE-2026-6269GitLab has remediated an issue in GitLab CE/EE affecting all…5.4
Are you affected by CVE-2026-62681?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
