critical · CVSS v3 9.8 · CVSS v4 9.3
CVE-2026-96757
orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string li…
Description
orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string literals in generated code. Attackers can inject JavaScript through crafted media-type keys in OpenAPI specifications that executes when generated fetch operations or mock resolvers are invoked.
Scores
- Severity
- critical
- CVSS v2
- 10
- CVSS v3
- 9.8
- CVSS v4
- 9.3
- EPSS
- —