12 Total advisories
12 Vulnerabilities
0 Malware
Dependency scanning
Check whether orval is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
UNKNOWN
CVE-2026-71869
Orval: Import-time RCE via array-items default -> zod module-level template literal
UNKNOWN
CVE-2026-71868
Orval: Import-time RCE via enum-typed default -> zod module-level template literal
UNKNOWN
CVE-2026-62681
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
UNKNOWN
CVE-2026-62682
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
UNKNOWN
CVE-2026-71864
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
UNKNOWN
CVE-2026-72717
Orval: Import-time RCE via schema default -> zod module-level template literal
UNKNOWN
CVE-2026-71865
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli
UNKNOWN
CVE-2026-71871
Orval: Import-time RCE via header-parameter default -> zod module-level template literal
UNKNOWN
CVE-2026-71867
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
UNKNOWN
CVE-2026-72716
Orval: Import-time RCE via query-parameter default -> zod module-level template literal
UNKNOWN
CVE-2026-71866
Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
HIGH 7.1
CVE-2026-62680
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes