@orval/core is vulnerable to Code Injection
81
High Risk
The @orval/core request generators embed OpenAPI request-body content-type keys into single-quoted TypeScript string literals without escaping single quotes. A content type containing a single quote closes the literal and injects arbitrary code into the generated request configuration. The code executes when the generated client is compiled by a transpiler that skips type checking and then run. The fix escapes content-type values at each emission site.
You are affected if you are using a version that falls within the vulnerable range and you generate request code from an untrusted or externally influenced OpenAPI document.
@orval/core is vulnerable to Code Injection in versions 6.11.0 - 8.28.1.
Upgrade the @orval/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.