@orval/core
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting @orval/corepage 1 of 1
- CVE-2026-23947CRITICALCVSS 9.8EG 9.8✓ Fixed in 8.0.22026-01-20
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions prior to 7.19.0 until 8.0.2 are vulnerable to arbitrary code execution in environments consuming generated clients. This issu…
- CVE-2026-25141CRITICALCVSS 9.8EG 9.8✓ Fixed in 7.21.02026-01-30
Orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Versions starting with 7.19.0 and prior to 7.21.0 and 8.2.0 have an incomplete fix for CVE-2026-23947. While the jsStringEscape functi…
Check whether @orval/core is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for @orval/core CVEs against the assets you own.
Start Free Scan →