GHSA-88f2-fpv8-89q2: Code Injection

Published Sep 3, 2026
·
Updated

Summary

When Orval is configured with output.baseUrl.getBaseUrlFromSpecification: true, it bakes the spec's servers[0].url into the generated request URL as a template literal without escaping the backtick. A server URL containing a backtick closes the template literal and injects a concatenation expression evaluated when the generated URL/request function is called, executing attacker-controlled code. Verified on Orval 8.19.0 (fetch client); survives default OpenAPI validation.

Details

ts return http://api.x/ + (globalThis.X = require("fs").writeFileSync("/marker","pwned")) + /v1/u;

Prerequisite: the documented getBaseUrlFromSpecification: true option (takes the base URL from the OpenAPI servers block). This is the same output sink as the route-path case (request-URL template literal) reached via the server url field. Distinct from Orval's published CVEs (CVE-2026-22785 summary/MCP, CVE-2026-23947 / CVE-2026-25141 x-enumDescriptions, CVE-2026-24132 const/mock).

PoC

reproduce.sh (+ makespec.py) attached: generates a fetch client with getBaseUrlFromSpecification: true, bundles it, calls the functions, and shows a marker written. Verified on 8.19.0.

Impact

With that option enabled, code execution in any environment that calls a client generated from an attacker-controlled or attacker-influenced OpenAPI description.

Suggested fix

Escape the server URL before emitting it into the URL template literal (escape backtick and ${), or build the base URL with an encoder that treats it as data; validate the URL. maintainer-report.txt makespec.py reproduce.sh

Affected Software

1 affected componentFixes available
npm/orval<8.21.0
8.21.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/orval to a version that resolves this vulnerability.

    Fixed in 8.21.0
  2. Configuration

    Escape the OpenAPI servers[0].url value before emitting it into the generated URL template literal when `output.baseUrl.getBaseUrlFromSpecification: true` is enabled (escape the backtick character and `${`), or build the base URL using an encoder that treats it strictly as data; validate the resulting URL.

    Orval (output.baseUrl.getBaseUrlFromSpecification) getBaseUrlFromSpecification = true

Event History

Sep 3, 2026
Advisory Published
via GitHub·07:06 PM
Data Sourced
via GitHub·07:06 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Is a standard Orval configuration affected?

The vulnerable path requires output.baseUrl.getBaseUrlFromSpecification to be set to true. This option causes Orval to take the base URL from the OpenAPI specification's servers block.

2

What access would an attacker need to exploit this?

An attacker would need to influence the server URL in the OpenAPI specification used for generation. The generated request URL or function must then be called for the injected expression to execute.

3

Will normal OpenAPI validation reject a malicious server URL?

No. The issue was verified to survive default OpenAPI validation, so relying on that validation alone will not prevent a backtick-containing server URL from reaching generated code.

4

How can I identify potentially affected generated clients?

Identify builds that enable getBaseUrlFromSpecification and inspect the source OpenAPI servers[0].url value for backticks or unexpected template-literal content. Generated fetch clients from such specifications should be treated as potentially unsafe when their request functions are invoked.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203