CVE-2026-71867
Last modified
CVE-2026-71867 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories without safe encoding. EPSS estimates a 0.48% chance of exploitation in the next 30 days.
Description
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated mock factory is called by tests or an MSW handler, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/core/src/getters/keys.ts function getKey and MSW mock generation. This issue is fixed in version 8.21.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| orval-labs | orval | < 8.21.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-71867?
How severe is CVE-2026-71867?
How do I fix CVE-2026-71867?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-71858Notepad++ is a free and open-source source code editor. Prio…5.4
- CVE-2026-7186Stored cross-site scripting in the URL dashboard widget in C…5.4
- CVE-2026-71862Checkmate is an open-source, self-hosted tool designed to tr…7.5
- CVE-2026-71864Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71865Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71866Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71868Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71869Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-7187Missing authentication for critical function vulnerability i…8.8
- CVE-2026-71870pypdf is a free and open-source pure-python PDF library. Pri…4.8
- CVE-2026-71871Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71878Missing authentication in initial setup functionality left e…9.2
Are you affected by CVE-2026-71867?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
