Description
I am reporting a code injection vulnerability in Orval’s mock generation pipeline affecting @orval/mock in both the 7.x and 8.x series. This issue is related in impact to the previously reported enum x-enumDescriptions (https://github.
Recommendation
Update the @orval/mock package to the latest compatible version. Followings are version details:
Affected version(s): **>= 8.0.0-rc.0, < 8.0.3 < 7.20.0** Patched version(s): **8.0.3 7.20.0**
References
Could your website be exposed too?
SmartScanner can check your website for Orval Mock Generation Code Injection via const and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Orval has a code injection via unsanitized x-enum-descriptions in enum generation - CVE-2026-23947
- Orval has Code Injection via unsanitized x-enum-descriptions using JS comments - CVE-2026-25141
- [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-claude-code - CVE-2026-44688
- [Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat - @theia/ai-code-completion - CVE-2026-44688


