CVEPublished 2026-08-19Modified 2026-09-090 articles on news6 live referencesNVD data

CVE-2026-71867

Vulnerability data via NVD (ingested)

CVSS v3.1
EPSS percentile
40
Exploit Prediction Scoring System · top 60% of all CVEs
Description

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated mock factory is called by tests or an MSW handler, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/core/src/getters/keys.ts function getKey and MSW mock generation. This issue is fixed in version 8.21.0.

Timeline
Published 2026-08-19
Modified 2026-09-09

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-71867 on GitHub.
We haven't classified any articles referencing CVE-2026-71867 yet. The external references above still apply.