CVE-2026-25141: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-25141 is a code injection vulnerability in the Orval OpenAPI client generator (@orval/core npm package) that represents an incomplete fix for a prior vulnerability, CVE-2026-23947. It affects Orval versions 7.19.0 through 7.20.x and 8.0.0 through 8.1.x. The flaw allows attackers to inject arbitrary JavaScript/TypeScript code into generated client files by supplying a maliciously crafted OpenAPI specification with poisoned x-enumDescriptions values. It was disclosed on January 30, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 9.3 (Critical) (GitHub Advisory GHSA-gch2-phqh-fg9q).

Technical details

The root cause is CWE-94 (Improper Control of Generation of Code / Code Injection) in the jsStringEscape function located in packages/core/src/utils/string.ts. While the prior fix for CVE-2026-23947 added escaping for single quotes, double quotes, and common special characters, it failed to sanitize * and / characters, enabling attackers to break out of JavaScript block comments using */ sequences embedded in x-enumDescriptions fields of an OpenAPI specification (GitHub Advisory GHSA-gch2-phqh-fg9q, string.ts source). Additionally, attackers can leverage JSFuck — a technique that encodes arbitrary JavaScript using only the characters []()!+ — to bypass sanitization entirely without requiring alphanumeric characters or quotes, making the bypass highly flexible (GitHub Advisory GHSA-gch2-phqh-fg9q). The attack vector is network-based (the malicious OpenAPI spec can be served remotely), requires no privileges, and no user interaction beyond running Orval against the spec.

Impact

Successful exploitation results in arbitrary code execution in any environment that consumes the generated client files — including developer workstations, CI/CD pipelines, and build servers. An attacker who can supply or influence the OpenAPI specification processed by Orval can achieve full confidentiality, integrity, and availability compromise of the affected system, including executing system commands (e.g., child_process.execSync), exfiltrating secrets, or establishing persistence (GitHub Advisory GHSA-gch2-phqh-fg9q). The supply-chain nature of this attack means that poisoned generated files could propagate to downstream consumers of the generated TypeScript/JavaScript clients, amplifying the blast radius beyond the initial build environment.

Exploitability

No public exploit kit or weaponized tool has been reported, but the advisory includes a working proof-of-concept OpenAPI specification demonstrating both the */ comment-escape technique and the JSFuck-based bypass (GitHub Advisory GHSA-gch2-phqh-fg9q). The EPSS score is approximately 0.051% (low probability of near-term exploitation), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution or confirmed in-the-wild exploitation has been reported as of the time of disclosure.

Exploitation steps

  1. Craft a malicious OpenAPI specification: Create an OpenAPI 3.x YAML or JSON file containing a schema with an x-enumDescriptions field. Embed a payload that breaks out of a JavaScript comment block using */ followed by arbitrary code, then re-opens a comment with /* to avoid syntax errors. Example payload value: "pwned */ }; import('child_process').then(cp => cp.execSync('touch pwned')); const a = { /*"
  2. Alternative — JSFuck bypass: If basic */ sequences are filtered, encode the malicious payload using JSFuck (using only []()!+ characters) to execute arbitrary JavaScript without alphanumeric characters or quotes, bypassing sanitization logic entirely.
  3. Deliver the malicious spec: Host the crafted OpenAPI spec on an attacker-controlled server, submit it to a target organization's API registry, or perform a supply-chain attack by contributing it to an open-source project that uses Orval for client generation.
  4. Trigger code generation: Wait for or induce the target to run Orval against the malicious spec (e.g., via a CI/CD pipeline, developer workflow, or automated tooling). Orval processes the x-enumDescriptions field and embeds the unsanitized value into generated TypeScript/JavaScript files.
  5. Achieve code execution: When the generated files are imported or executed in a Node.js environment (e.g., during build, test, or runtime), the injected code runs with the privileges of the process, enabling command execution, data exfiltration, or further lateral movement (GitHub Advisory GHSA-gch2-phqh-fg9q).

Indicators of compromise

  • File System: Generated TypeScript/JavaScript client files containing unexpected */ sequences followed by executable code blocks outside of normal comment or string contexts; presence of files like pwned or other unexpected artifacts in the build directory after running Orval.
  • File System: Generated schema files with JSFuck-style payloads (long strings composed exclusively of []()!+ characters) embedded in enum-related code sections.
  • Logs: CI/CD pipeline logs showing unexpected child process spawning (e.g., touch, curl, wget, bash) during or immediately after Orval code generation steps.
  • Process: Unexpected child processes (e.g., sh, bash, node -e) spawned by the Node.js process running Orval during build or code generation.
  • Network: Outbound connections to unknown external hosts originating from the build server or developer workstation during or after Orval execution, potentially indicating data exfiltration or C2 callback.

Mitigation and workarounds

Orval-labs has released patched versions that fully address this vulnerability: v7.21.0 (for the 7.x branch) and v8.2.0 (for the 8.x branch), both released on January 30, 2026 (v7.21.0 release, v8.2.0 release). The fix updates jsStringEscape to also escape /* and */ sequences, preventing comment-block escape attacks. As an interim workaround, avoid processing untrusted or externally sourced OpenAPI specifications with vulnerable Orval versions. Organizations should audit any generated files produced by affected versions for signs of injected code before deploying them.

Community reactions

Security news outlet SecurityOnline.info covered the vulnerability under the headline "Poisoned Comments: Critical Orval Flaw CVE-2026-25141 Injects Code," highlighting the comment-escape technique (SecurityOnline). The vulnerability was also noted on Bluesky by the infosec community (Bluesky post). The advisory credits researcher progfay as the finder and k14uz as the analyst, indicating responsible disclosure through GitHub's security advisory process (GitHub Advisory GHSA-gch2-phqh-fg9q).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management