CVE-2026-62682 | orval-labs Orval up to 8.20.x Route Getter route.ts getFullRoute url cross site scripting

SecurityVulns

A vulnerability marked as problematic has been reported in orval-labs Orval up to 8.20.x. Affected is the function getFullRoute of the file packages/core/src/getters/route.ts of the component Route Getter. This manipulation of the argument url causes cross site scripting.

This vulnerability is handled as CVE-2026-62682. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More