Vulnerabilities/

Orval has a code injection via unsanitized x-enum-descriptions in enum generation

Severity:
High

Description

Arbitrary code execution in environments consuming generated clients

This issue is similar in nature to the recently-patched MCP vulnerability (CVE-2026-22785), but affects a different code path in @orval/core that was not addressed by that fix.

Recommendation

Update the @orval/core package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@orval/core
Anything's wrong? Let us know Last updated on February 27, 2026