CVE-2026-96759
Last modified
CVE-2026-96759 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript code through a crafted operationId in an OpenAPI specification that executes when generated hooks are called..
Description
orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator options metadata objects. Attackers can inject arbitrary JavaScript code through a crafted operationId in an OpenAPI specification that executes when generated hooks are called.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| orval-labs | orval | < 8.29.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-96759?
How severe is CVE-2026-96759?
How do I fix CVE-2026-96759?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-9675Impact: The undici WebSocket client enforces maxPayloadSize …7.5
- CVE-2026-96754orval versions before 8.29.0 contain a code injection vulner…9.8
- CVE-2026-96755orval versions 8.14.0 through 8.28.1 contain a code injectio…9.8
- CVE-2026-96756orval versions before 8.30.0 contain a code injection vulner…8.1
- CVE-2026-96757orval before 8.29.0 fails to escape OpenAPI media-type keys …9.8
- CVE-2026-96758orval @orval/core before 8.28.0 contains a code injection vu…9.8
- CVE-2026-9676The F4 Post Tree WordPress plugin before 2.0.5 does not perf…4.3
- CVE-2026-9677The Shariff for WordPress Shariff for WordPress plugin throu…4.8
- CVE-2026-96775MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_A…8.8
- CVE-2026-9678Impact: Undici's cache interceptor incorrectly classifies so…5.9
- CVE-2026-9679Impact: undici's cookie parser in parseSetCookie percent-dec…5.9
- CVE-2026-9680Improper exposure of the MCP server in alibabacloud-rds-open…5.8
Are you affected by CVE-2026-96759?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
