12 Total advisories
12 Vulnerabilities
0 Malware

Dependency scanning

Check whether orval is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
npm

CVE-2026-71869

Orval: Import-time RCE via array-items default -> zod module-level template literal

UNKNOWN
npm

CVE-2026-71868

Orval: Import-time RCE via enum-typed default -> zod module-level template literal

UNKNOWN
npm

CVE-2026-62681

Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)

UNKNOWN
npm

CVE-2026-62682

Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)

UNKNOWN
npm

CVE-2026-71864

Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client

UNKNOWN
npm

CVE-2026-72717

Orval: Import-time RCE via schema default -> zod module-level template literal

UNKNOWN
npm

CVE-2026-71865

Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli

UNKNOWN
npm

CVE-2026-71871

Orval: Import-time RCE via header-parameter default -> zod module-level template literal

UNKNOWN
npm

CVE-2026-71867

Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator

UNKNOWN
npm

CVE-2026-72716

Orval: Import-time RCE via query-parameter default -> zod module-level template literal

UNKNOWN
npm

CVE-2026-71866

Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client

HIGH 7.1
npm

CVE-2026-62680

Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes