Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-22785: Code injection in orval MCP server generation from OpenAPI specs

Versions of orval before 7.18.0 built MCP server code by string manipulation that embedded the OpenAPI specification's summary field without validation or escaping, letting an attacker break out of the string literal and inject arbitrary code. The issue is fixed in orval 7.18.0.

Disclosed 12 January 2026 · Record updated 13 September 2026

Impact

A crafted OpenAPI/Swagger specification could cause arbitrary code to be injected into the generated MCP server client code.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-22785