Orval client generator can run attacker code
Orval is a developer tool that turns API description files into ready to use code. A booby trapped API description can make Orval run the attacker's own commands on the machine that generates the code.
- Severity
- CriticalCVSS 4.0 · 9.3
- Fix
- Fixed in 8.21.0Fix recorded on Sep 3, 2026
- Affected versions
- before 8.21.0
- Weakness
- CWE-94Code Injection
- Exploit likelihood
- 0.62% in 30 daysEPSS, higher than 48% of known flaws
- Affects
- orval
How it works
When a developer turns on Orval's option to pull the base web address straight from the API description, Orval drops that address into generated code without checking it for stray characters, so a description containing a backtick character can break out of the address text and add real, executable code that runs the moment the generated function is called.
What to do
Run npm list orval in your project to see the installed version, and check your orval config for output.baseUrl.getBaseUrlFromSpecification set to true. If you use that option and generate clients from any OpenAPI or Swagger file you do not fully control, you are exposed on versions older than 8.21.0.
Run this in the application environment you want to check:
npm list orvalUpdate to orval 8.21.0 or later with npm install orval@8.21.0, and until you update, avoid the getBaseUrlFromSpecification option or only use it with OpenAPI files from sources you fully trust.
Technical details
The bug sits in packages/core/src/getters/route.ts, function getFullRoute. When output.baseUrl.getBaseUrlFromSpecification is enabled, Orval writes servers[0].url from the OpenAPI spec directly into a generated JavaScript template literal without escaping backticks. A server URL containing a backtick and a JavaScript expression closes the literal early and gets evaluated as real code when the generated request or URL builder function runs, giving the attacker code execution in whatever environment calls that generated code, developer machine, CI runner, test environment, or the deployed application.
It is tracked as CWE-94 code injection. Fixed in orval 8.21.0.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low No extra steps to bypass built-in attack protections
- Required conditions None No particular deployment or execution condition is required
- Privileges required None Attacker needs no account or login
- User action None No action by another user is required
- Vulnerable system: Data exposure High Sensitive data can be exposed with serious impact
- Vulnerable system: Data changes High Protected data can be changed with serious impact
- Vulnerable system: Service disruption High The service can stop or suffer serious disruption
- Other systems: Data exposure None No additional impact beyond the vulnerable system
- Other systems: Data changes None No additional impact beyond the vulnerable system
- Other systems: Service disruption None No additional impact beyond the vulnerable system
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Open in FIRST.org calculatorReferences
- github.com · v8.21.0 (tag) patch release notes vendor advisory
- github.com · GHSA-88f2-fpv8-89q2 vendor advisory
- nvd.nist.gov · CVE-2026-62682 vdb entry us government resource
- github.com · PR #3692 GitHub Advisory vendor advisory
- github.com · commit 8ef1bfd GitHub Advisory vendor advisory
- tenable.com · CVE-2026-62682 third party advisory vdb entry
- cvefeed.io · CVE-2026-62682 third party advisory vdb entry
- osv.dev · CVE-2026-62682 vdb entry