@orval/core is vulnerable to Code Injection
86
High Risk
@orval/core fails to sanitize numeric const values when generating TypeScript models, so a schema that declares a numeric type but supplies a string const escapes the numeric context. The unescaped value is spliced into a generated type and value declaration, injecting arbitrary code. The code executes when the generated models are imported as runtime modules. The fix renders mismatched const values as safe literal types.
You are affected if you are using a version that falls within the vulnerable range and you generate models from an untrusted or externally influenced OpenAPI document.
@orval/core is vulnerable to Code Injection in versions 8.23.0 - 8.29.0.
Upgrade the @orval/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.