GHSA-88f2-fpv8-89q2

Suggest an improvement
Source
https://github.com/advisories/GHSA-88f2-fpv8-89q2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-88f2-fpv8-89q2/GHSA-88f2-fpv8-89q2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-88f2-fpv8-89q2
Aliases
Published
2026-09-03T19:06:52Z
Modified
2026-09-03T19:15:04Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
Details

Summary

When Orval is configured with output.baseUrl.getBaseUrlFromSpecification: true, it bakes the spec's servers[0].url into the generated request URL as a template literal without escaping the backtick. A server URL containing a backtick closes the template literal and injects a concatenation expression evaluated when the generated URL/request function is called, executing attacker-controlled code. Verified on Orval 8.19.0 (fetch client); survives default OpenAPI validation.

Details

return `http://api.x/` + (globalThis.X = require("fs").writeFileSync("/marker","pwned")) + `/v1/u`;

Prerequisite: the documented getBaseUrlFromSpecification: true option (takes the base URL from the OpenAPI servers block). This is the same output sink as the route-path case (request-URL template literal) reached via the server url field. Distinct from Orval's published CVEs (CVE-2026-22785 summary/MCP, CVE-2026-23947 / CVE-2026-25141 x-enumDescriptions, CVE-2026-24132 const/mock).

PoC

reproduce.sh (+ make_spec.py) attached: generates a fetch client with getBaseUrlFromSpecification: true, bundles it, calls the functions, and shows a marker written. Verified on 8.19.0.

Impact

With that option enabled, code execution in any environment that calls a client generated from an attacker-controlled or attacker-influenced OpenAPI description.

Suggested fix

Escape the server URL before emitting it into the URL template literal (escape backtick and ${), or build the base URL with an encoder that treats it as data; validate the URL. maintainer-report.txt make_spec.py reproduce.sh

Database specific
{
    "cwe_ids": [
        "CWE-94",
        "CWE-116",
        "CWE-1336"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-03T19:06:52Z",
    "nvd_published_at": "2026-08-19T18:16:54Z",
    "severity": "CRITICAL"
}
References

Affected packages

npm / orval

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.21.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-88f2-fpv8-89q2/GHSA-88f2-fpv8-89q2.json"