CVE-2026-22785 is a critical code injection vulnerability in Orval’s MCP server generation logic. In Orval versions prior to 7.18.0, the code generation path incorporates the OpenAPI specification’s summary field into generated JavaScript/TypeScript using unsafe string manipulation without proper validation or escaping. A malicious OpenAPI v3 or Swagger v2 document can therefore supply a crafted summary value that breaks out of the intended string literal and injects attacker-controlled code into the generated output. The issue affects the MCP client/server generation path and was fixed in version 7.18.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: a small PoC/utility to reproduce CVE-2026-22785 (orval < 7.18.0) code injection during MCP server code generation, plus a basic file scanner. Structure: - README.md: Chinese reproduction guide; explains that OpenAPI `summary` is concatenated into templates without escaping, enabling code injection. Shows an example injected line in generated `server.ts` calling `require('child_process').execSync('whoami', {})`. - cve_tool.py: Main entry point. Implements two subcommands: - `shell <command>`: crafts `exploit/malicious-openapi.yaml` with an injected JavaScript payload in the `summary` field, runs `npx orval -i malicious-openapi.yaml -o gen.mjs --client mcp` in `exploit/`, checks generated `gen.mjs` for `child_process`, locates the injection line in `exploit/server.ts`, then executes the user-supplied command locally via `subprocess.run(command, shell=True)`. - `scan <file>`: simple regex-based detection for suspicious Node patterns (CRITICAL: `child_process|execSync|spawn|eval(`; HIGH: `fs.|readFile|writeFile|fetch(`) and flags likely CVE-2026-22785 samples. - exploit/package.json: sets up a reproducible vulnerable environment by pinning `orval` to 7.17.0. Exploit capability: arbitrary command execution on the system performing code generation (developer/CI machine) by supplying a malicious OpenAPI spec; the payload is a Node.js `child_process.execSync` injection embedded into generated MCP server code. No network scanning or remote endpoints are used; the attack is primarily local/supply-chain via processing untrusted OpenAPI input.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical code injection vulnerability in Orval where untrusted OpenAPI summary content is concatenated into generated code, enabling arbitrary JavaScript execution.
A recently patched MCP vulnerability referenced for similarity; details are not provided in the content beyond being similar in nature to the Orval injection issue.
A critical code injection vulnerability in orval’s MCP server generation logic where unescaped OpenAPI/Swagger "summary" content can break out of a string literal during code generation, enabling arbitrary code injection. Fixed in orval 7.18.0.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.