GHSA-6437-gxhq-pqv8: Code Injection

Published Sep 3, 2026
·
Updated

Summary

orval's zod client emits each header parameter name as a double-quoted key in the generated zod.object({...}) request-validation schema WITHOUT escaping the double quote. A " in the header parameter name closes the key and lands in object-literal context, where an injected computed property key [expr] is evaluated when zod.object({...}) runs -- at MODULE IMPORT (export const OpHeader = zod.object({...}) executes on load) -> import-time RCE. The header parameter name is a pure data field. Verified on orval 8.19.0 / Node.

Details

export const OpHeader = zod.object({ "a":zod.string(),[require("fs").writeFileSync("PWNED","")]:zod.string(),"b": ... })

Also affects the hono client (reuses zod generation). orval escapes values in zod arrays but not keys in zod.object. Sibling fields: schema property name, query parameter name (CVE-96) (separate reports). Distinct from orval's $ref / route-path / server-url / zod-default findings.

PoC

reproduce.sh (+ makespec.py) attached: a header parameter name that breaks the zod.object key and injects a computed key; evaluating it (= importing the module) writes the marker. Verified on 8.19.0.

Impact

JavaScript / OS command execution at import time for anyone who generates an orval zod client from an attacker-controlled spec and imports it.

Suggested fix

Escape the header parameter name for the JS string key (JSON.stringify) in the zod.object key generation; never interpolate a raw name adjacent to [ ] in object-literal position.

Affected Software

1 affected componentFixes available
npm/orval<8.21.0
8.21.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/orval to a version that resolves this vulnerability.

    Fixed in 8.21.0

Event History

Sep 3, 2026
Advisory Published
via GitHub·06:08 PM
Data Sourced
via GitHub·06:08 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Projects that generate Zod clients with orval from API specifications containing attacker-controlled or otherwise untrusted header parameter names are exposed. The Hono client is also affected because it reuses the Zod generation path.

2

What does an attacker need to exploit it?

An attacker needs to cause a header parameter name containing a double quote and injected computed-property expression to be processed during client generation. The resulting generated JavaScript executes the expression when the generated module is imported.

3

What can be done if patching is not immediately possible?

Do not generate or import clients from untrusted API specifications. Review header parameter names before generation and reject names containing double quotes or other content that could break a generated object key.

4

How can I determine whether generated code is already dangerous?

Inspect generated Zod request-validation schemas for header objects with malformed quoted keys or unexpected computed property keys such as bracketed expressions. Treat affected generated modules as unsafe to import, because execution occurs at module load time.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203