VDB
Sign up
CRITICAL

GHSA-h526-wf6g-67jv

Orval has a code injection via unsanitized x-enum-descriptions in enum generation

Quick fix

GHSA-h526-wf6g-67jv — @orval/core: upgrade to the fixed version with the command below.

npm install @orval/core@8.0.2

Details

### Impact Arbitrary code execution in environments consuming generated clients

This issue is similar in nature to the recently-patched MCP vulnerability (CVE-2026-22785), but affects a different code path in @orval/core that was not addressed by that fix.

The vulnerability allows untrusted OpenAPI specifications to inject arbitrary TypeScript/JavaScript code into generated clients via the x-enumDescriptions field, which is embedded without proper escaping in getEnumImplementation(). I have confirmed that the injection occurs during const enum generation and results in executable code within the generated schema files.

### Patches Upgrade to Orval 8.0.2

### References An example OpenAPI showing the issue:

```yaml openapi: 3.0.4 info: title: Enum PoC version: "1.0.0"

paths: /ping: get: operationId: ping responses: "200": description: ok content: application/json: schema: $ref: "#/components/schemas/EvilEnum"

components: schemas: EvilEnum: type: string enum: - PWNED x-enumDescriptions: - "pwned */ require('child_process').execSync('id'); /*" ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@orval/core
Introduced in: 8.0.0-rc.0Fixed in: 8.0.2
Fixnpm install @orval/core@8.0.2
npm/@orval/core
Introduced in: 0Fixed in: 7.19.0
Fixnpm install @orval/core@7.19.0

References