Description
I am reporting a code injection vulnerability in Orval’s mock generation pipeline affecting @orval/mock in both the 7.x and 8.x series. This issue is related in impact to the previously reported enum x-enumDescriptions (https://github.
Recommendation
Update the @orval/mock package to the latest compatible version. Followings are version details:
Affected version(s): **>= 8.0.0-rc.0, < 8.0.3 < 7.20.0** Patched version(s): **8.0.3 7.20.0**
References
Related Issues
- Orval has a code injection via unsanitized x-enum-descriptions in enum generation - CVE-2026-23947
- Orval has Code Injection via unsanitized x-enum-descriptions using JS comments - CVE-2026-25141
- [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-claude-code - CVE-2026-44688
- [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-code-completion - CVE-2026-44688
You might also like:
- Tags:
- npm
- @orval/mock
Anything's wrong? Let us know Last updated on February 27, 2026


