Vulnerability library
Security checkFebruary 27, 2026

Orval has a code injection via unsanitized x-enum-descriptions in enum generation

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpm@orval/core

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

Arbitrary code execution in environments consuming generated clients

This issue is similar in nature to the recently-patched MCP vulnerability (CVE-2026-22785), but affects a different code path in @orval/core that was not addressed by that fix.

Recommendation

Update the @orval/core package to the latest compatible version. Followings are version details:

  • Affected version(s): **< 7.19.0 >= 8.0.0-rc.0, < 8.0.2**
  • Patched version(s): **7.19.0 8.0.2**

References

Could your website be exposed too?

SmartScanner can check your website for Orval has a code injection via unsanitized x-enum-descriptions in enum generation and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated February 27, 2026