Retour à la veille

CVE-2026-96758

Publié : 23 septembre 2026
Modifié : 23 septembre 2026
Lien officiel NVD
Score CVSS
9.8
CRITICAL

Description détaillée

orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape multipart property names in generated template literals. Attackers can inject ${...} expressions into OpenAPI schema property names that execute as live interpolation when the generated client builds FormData bodies with consumer process privileges.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Références et Patchs