GHSA-cxq5-97v7-87j8
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
Quick fix
GHSA-cxq5-97v7-87j8 — orval: upgrade to the fixed version with the command below.
npm install orval@8.22.0Details
### Summary
Orval resolves OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files (including absolute / out-of-tree paths), inlining the referenced schema into the generated client. Running `orval` on a spec whose `$ref` points at an attacker/internal URL or an arbitrary local file yields SSRF, remote file inclusion, and local file inclusion. Verified on 8.19.0. This is a different class from Orval's published output-injection CVEs (CVE-2026-22785/23947/24132/25141), none of which covers the `$ref` resolver.
### Details
- `$ref: http://attacker/internal-evil.json#/...` → build host fetches (SSRF) and inlines the remote schema (RFI); confirmed property `REMOTE_ORVAL_PROP` in the generated client. - `$ref: /abs/path.json#/...` or `../../secret.json#/...` → out-of-tree local file read + inlined (LFI).
No RCE: on 8.19.0 the description JSDoc is escaped (`*/`->`*\/`, the published fix), so `$ref` content cannot break out into code. The chain stops at SSRF + RFI + LFI.
Fix: don't resolve remote `$ref`s by default (opt-in + host allowlist); confine local `$ref` resolution to the input directory tree (reject absolute paths and `../` escapes).
### PoC
`reproduce.sh` attached: confirms LFI (out-of-tree read), SSRF (listener hit), RFI (remote schema inlined). Verified on Orval 8.19.0.
### Impact
Build-time SSRF from the developer or CI host, disclosure of arbitrary local files, and inclusion of untrusted remote content, from running the generator on an attacker-controlled or attacker-influenced OpenAPI description. No code execution (output escaping is in place post the earlier fixes).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/orval-labs/orval/security/advisories/GHSA-cxq5-97v7-87j8[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-62680[ADVISORY]
- https://github.com/orval-labs/orval/pull/3692[WEB]
- https://github.com/orval-labs/orval/pull/3723[WEB]
- https://github.com/orval-labs/orval/commit/23786c056f4eba38c02bf2968677988dbbe4de10[WEB]
- https://github.com/orval-labs/orval/commit/8ef1bfdf3f9bcaf9dabfbe2e42887f1c0e159ab6[WEB]
- https://github.com/orval-labs/orval[PACKAGE]
- https://github.com/orval-labs/orval/releases/tag/v8.22.0[WEB]