Orval mock generator bug can run attacker code

Published September 3, 2026 CVE-2026-71867

Orval is a tool developers use to auto-generate test code from an API specification. A booby-trapped spec file can slip in commands that run on the developer's or CI machine the moment the generated tests execute.

Severity
CriticalCVSS 4.0 · 9.3
Fix
Fixed in 8.21.0Fix recorded on Sep 3, 2026
Affected versions
before 8.21.0
Weakness
CWE-89SQL Injection
Exploit likelihood
0.61% in 30 daysEPSS, higher than 47% of known flaws
Affects
Orval+1 more

How it works

Orval copies each field name straight from the API specification into generated mock test code without cleaning it, so a field name containing a stray quote mark lets an attacker's own code slip into that generated file and run.

What to do

Run npm ls orval in your project to see the installed version; you are exposed only if it is older than 8.21.0 and your Orval config has output.mock set to true.

Run this in the application environment you want to check:

npm ls orval

Update to Orval 8.21.0 or later with npm install orval@8.21.0 or later, and treat any OpenAPI spec from an untrusted source as untrusted code before generating mocks from it.

Technical details

Affected software: Orval, MSW

The bug is in packages/core/src/getters/keys.ts (function getKey), which emits each OpenAPI schema property name as a single-quoted JavaScript object key inside generated MSW mock factories without escaping embedded single quotes. A property name containing a quote can close the key early and inject a computed property key ([expr]) that JavaScript evaluates when the mock factory function is called, such as during test runs. This allows arbitrary JavaScript, including Node's child_process or fs modules, to execute in the developer, CI, test, or application environment. It is fixed in Orval 8.21.0 by properly encoding property names with JSON.stringify.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low No extra steps to bypass built-in attack protections
  • Required conditions None No particular deployment or execution condition is required
  • Privileges required None Attacker needs no account or login
  • User action None No action by another user is required
  • Vulnerable system: Data exposure High Sensitive data can be exposed with serious impact
  • Vulnerable system: Data changes High Protected data can be changed with serious impact
  • Vulnerable system: Service disruption High The service can stop or suffer serious disruption
  • Other systems: Data exposure None No additional impact beyond the vulnerable system
  • Other systems: Data changes None No additional impact beyond the vulnerable system
  • Other systems: Service disruption None No additional impact beyond the vulnerable system
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Open in FIRST.org calculator

References