Severity: critical
CVE: CVE-2026-71867
Package: orval @ 8.5.3
Vulnerable range: <8.21.0
Patched in: >=8.21.0
Dep paths:
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
Reference: GHSA-2w86-xfrc-g85r
Filed automatically by .github/workflows/pnpm-audit.yml. The fix
work for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md §11 limitation 4 for the
policy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to scripts/audit/ignore-list.json
with a written reachability rationale and a re-evaluation date.
Severity: critical
CVE: CVE-2026-71867
Package:
orval@8.5.3Vulnerable range:
<8.21.0Patched in:
>=8.21.0Dep paths:
lib__api-spec>orvalReference: GHSA-2w86-xfrc-g85r
Filed automatically by
.github/workflows/pnpm-audit.yml. The fixwork for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md§11 limitation 4 for thepolicy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to
scripts/audit/ignore-list.jsonwith a written reachability rationale and a re-evaluation date.