GHSA-6437-gxhq-pqv8

    Dashboard / Vulnerabilities / GHSA-6437-gxhq-pqv8

    GHSA-6437-gxhq-pqv8

    Published: 3 Sept 2026Last Modified: 3 Sept 2026

    Summary: Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client

    Details: ### Summary orval's zod client emits each header parameter name as a double-quoted key in the generated zod.object({...}) request-validation schema WITHOUT escaping the double quote. A " in the header parameter name closes the key and lands in object-literal context, where an injected computed property key [expr] is evaluated when zod.object({...}) runs -- at MODULE IMPORT (export const OpHeader = zod.object({...}) executes on load) -> import-time RCE. The header parameter name is a pure data field. Verified on orval 8.19.0 / Node. ### Details export const OpHeader = zod.object({ "a":zod.string(),[require("fs").writeFileSync("PWNED","")]:zod.string(),"b": ... }) Also affects the hono client (reuses zod generation). orval escapes values in zod arrays but not keys in zod.object. Sibling fields: schema property name, query parameter name (CVE-96) (separate reports). Distinct from orval's $ref / route-path / server-url / zod-default findings. ### PoC reproduce.sh (+ make_spec.py) attached: a header parameter name that breaks the zod.object key and injects a computed key; evaluating it (= importing the module) writes the marker. Verified on 8.19.0. ### Impact JavaScript / OS command execution at import time for anyone who generates an orval zod client from an attacker-controlled spec and imports it. ### Suggested fix Escape the header parameter name for the JS string key (JSON.stringify) in the zod.object key generation; never interpolate a raw name adjacent to [ ] in object-literal position.

    Affected packages

    Package

    Name: orval

    Purl: pkg:npm/orval

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -8.21.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High