GHSA-88f2-fpv8-89q2

    Dashboard / Vulnerabilities / GHSA-88f2-fpv8-89q2

    GHSA-88f2-fpv8-89q2

    Published: 3 Sept 2026Last Modified: 3 Sept 2026

    Summary: Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)

    Details: ### Summary When Orval is configured with `output.baseUrl.getBaseUrlFromSpecification: true`, it bakes the spec's `servers[0].url` into the generated request URL as a template literal without escaping the backtick. A server URL containing a backtick closes the template literal and injects a concatenation expression evaluated when the generated URL/request function is called, executing attacker-controlled code. Verified on Orval 8.19.0 (fetch client); survives default OpenAPI validation. ### Details ```ts return `http://api.x/` + (globalThis.X = require("fs").writeFileSync("/marker","pwned")) + `/v1/u`; ``` Prerequisite: the documented `getBaseUrlFromSpecification: true` option (takes the base URL from the OpenAPI servers block). This is the same output sink as the route-path case (request-URL template literal) reached via the server `url` field. Distinct from Orval's published CVEs (CVE-2026-22785 summary/MCP, CVE-2026-23947 / CVE-2026-25141 x-enumDescriptions, CVE-2026-24132 const/mock). ### PoC `reproduce.sh` (+ `make_spec.py`) attached: generates a fetch client with `getBaseUrlFromSpecification: true`, bundles it, calls the functions, and shows a marker written. Verified on 8.19.0. ### Impact With that option enabled, code execution in any environment that calls a client generated from an attacker-controlled or attacker-influenced OpenAPI description. ### Suggested fix Escape the server URL before emitting it into the URL template literal (escape backtick and `${`), or build the base URL with an encoder that treats it as data; validate the URL. [maintainer-report.txt](https://github.com/user-attachments/files/29396562/maintainer-report.txt) [make_spec.py](https://github.com/user-attachments/files/29396563/make_spec.py) [reproduce.sh](https://github.com/user-attachments/files/29396564/reproduce.sh)

    Affected packages

    Package

    Name: orval

    Purl: pkg:npm/orval

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -8.21.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High