CVE-2026-72716 | orval-labs Orval up to 8.20.x Zod Schema Generation index.ts formatDefaultValue code injection

SecurityVulns

A vulnerability classified as critical was found in orval-labs Orval up to 8.20.x. Affected is the function formatDefaultValue of the file packages/zod/src/index.ts of the component Zod Schema Generation. Such manipulation leads to code injection.

This vulnerability is referenced as CVE-2026-72716. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More