CVE-2026-23947 is a critical code injection vulnerability in Orval/@orval/core, a tool that generates type-safe TypeScript/JavaScript clients from OpenAPI v3 and Swagger v2 specifications. The flaw affects vulnerable Orval versions prior to the fixed releases and is triggered when Orval processes an untrusted OpenAPI specification containing attacker-controlled data in the x-enumDescriptions field. In the vulnerable code path, getEnumImplementation() embeds x-enumDescriptions into generated code during const enum generation without proper escaping, allowing arbitrary TypeScript/JavaScript to be injected into generated schema/client files. The issue is described as similar to CVE-2026-22785 but affecting a different @orval/core code path that was not addressed by the earlier fix.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical code injection vulnerability in Orval where untrusted x-enumDescriptions content is embedded into generated code/comments without escaping, enabling arbitrary JavaScript execution.
Earlier Orval vulnerability of the same general class (code injection via incomplete sanitization) whose patch was bypassed by CVE-2026-25141 due to an incomplete fix.
A critical code injection vulnerability in Orval (@orval/core) where untrusted OpenAPI specifications can inject arbitrary TypeScript/JavaScript into generated client code via the x-enum-descriptions field, leading to arbitrary code execution in environments that consume the generated clients (software supply chain risk).
Arbitrary code injection leading to code execution in Orval-generated TypeScript/JavaScript clients when processing untrusted OpenAPI/Swagger specifications; injection occurs via the x-enumDescriptions field during enum generation due to improper escaping in @orval/core.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.