Orval client generator can run attacker code

Published September 3, 2026 CVE-2026-62682

Orval is a developer tool that turns API description files into ready to use code. A booby trapped API description can make Orval run the attacker's own commands on the machine that generates the code.

Severity
CriticalCVSS 4.0 · 9.3
Fix
Fixed in 8.21.0Fix recorded on Sep 3, 2026
Affected versions
before 8.21.0
Weakness
CWE-94Code Injection
Exploit likelihood
0.62% in 30 daysEPSS, higher than 48% of known flaws
Affects
orval

How it works

When a developer turns on Orval's option to pull the base web address straight from the API description, Orval drops that address into generated code without checking it for stray characters, so a description containing a backtick character can break out of the address text and add real, executable code that runs the moment the generated function is called.

What to do

Run npm list orval in your project to see the installed version, and check your orval config for output.baseUrl.getBaseUrlFromSpecification set to true. If you use that option and generate clients from any OpenAPI or Swagger file you do not fully control, you are exposed on versions older than 8.21.0.

Run this in the application environment you want to check:

npm list orval

Update to orval 8.21.0 or later with npm install orval@8.21.0, and until you update, avoid the getBaseUrlFromSpecification option or only use it with OpenAPI files from sources you fully trust.

Technical details

The bug sits in packages/core/src/getters/route.ts, function getFullRoute. When output.baseUrl.getBaseUrlFromSpecification is enabled, Orval writes servers[0].url from the OpenAPI spec directly into a generated JavaScript template literal without escaping backticks. A server URL containing a backtick and a JavaScript expression closes the literal early and gets evaluated as real code when the generated request or URL builder function runs, giving the attacker code execution in whatever environment calls that generated code, developer machine, CI runner, test environment, or the deployed application.

It is tracked as CWE-94 code injection. Fixed in orval 8.21.0.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low No extra steps to bypass built-in attack protections
  • Required conditions None No particular deployment or execution condition is required
  • Privileges required None Attacker needs no account or login
  • User action None No action by another user is required
  • Vulnerable system: Data exposure High Sensitive data can be exposed with serious impact
  • Vulnerable system: Data changes High Protected data can be changed with serious impact
  • Vulnerable system: Service disruption High The service can stop or suffer serious disruption
  • Other systems: Data exposure None No additional impact beyond the vulnerable system
  • Other systems: Data changes None No additional impact beyond the vulnerable system
  • Other systems: Service disruption None No additional impact beyond the vulnerable system
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Open in FIRST.org calculator

References