GHSA-2w86-xfrc-g85r

    Dashboard / Vulnerabilities / GHSA-2w86-xfrc-g85r

    GHSA-2w86-xfrc-g85r

    Published: 3 Sept 2026Last Modified: 3 Sept 2026

    Summary: Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator

    Details: ### Summary orval, when generating MSW mocks (output.mock: true), emits each schema property name as a single-quoted object key in the mock factory WITHOUT escaping the single quote. A ' in a property name closes the key and lands in object-literal context, where an injected computed property key [expr] is evaluated when the mock factory is called (e.g. in tests / MSW handlers) -> RCE. The property name is a pure data field. Verified on orval 8.19.0 / Node. ### Details ```ts export const getOpResponseMock = (...): Thing => ({'x': 0, [require("fs").writeFileSync("PWNED","")]: 0, 'y': faker...., ...overrideResponse}); ``` Safe elsewhere: the zod schema double-quotes the property name; the TS interface key is a type (DoS only). Distinct from orval's $ref / route-path / server-url / zod-default findings. ### PoC reproduce.sh (+ make_spec.py) attached: a property name `x': 0, [require("fs").writeFileSync("<marker>","")]: 0, 'y` -> mock object literal; calling the mock factory writes the marker. Verified on 8.19.0. ### Impact JavaScript / OS command execution (via child_process) on the machine of anyone who generates orval mocks from an attacker controlled spec and runs them (tests / MSW). ### Suggested fix Escape the property name for the JS string key (JSON.stringify), and never interpolate a raw property name adjacent to [ ] in object-literal position.

    Affected packages

    Package

    Name: orval

    Purl: pkg:npm/orval

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -8.21.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High