Orval mock generator bug can run attacker code
Orval is a tool developers use to auto-generate test code from an API specification. A booby-trapped spec file can slip in commands that run on the developer's or CI machine the moment the generated tests execute.
- Severity
- CriticalCVSS 4.0 · 9.3
- Fix
- Fixed in 8.21.0Fix recorded on Sep 3, 2026
- Affected versions
- before 8.21.0
- Weakness
- CWE-89SQL Injection
- Exploit likelihood
- 0.61% in 30 daysEPSS, higher than 47% of known flaws
- Affects
- Orval+1 more
How it works
Orval copies each field name straight from the API specification into generated mock test code without cleaning it, so a field name containing a stray quote mark lets an attacker's own code slip into that generated file and run.
What to do
Run npm ls orval in your project to see the installed version; you are exposed only if it is older than 8.21.0 and your Orval config has output.mock set to true.
Run this in the application environment you want to check:
npm ls orvalUpdate to Orval 8.21.0 or later with npm install orval@8.21.0 or later, and treat any OpenAPI spec from an untrusted source as untrusted code before generating mocks from it.
Technical details
Affected software: Orval, MSW
The bug is in packages/core/src/getters/keys.ts (function getKey), which emits each OpenAPI schema property name as a single-quoted JavaScript object key inside generated MSW mock factories without escaping embedded single quotes. A property name containing a quote can close the key early and inject a computed property key ([expr]) that JavaScript evaluates when the mock factory function is called, such as during test runs. This allows arbitrary JavaScript, including Node's child_process or fs modules, to execute in the developer, CI, test, or application environment. It is fixed in Orval 8.21.0 by properly encoding property names with JSON.stringify.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low No extra steps to bypass built-in attack protections
- Required conditions None No particular deployment or execution condition is required
- Privileges required None Attacker needs no account or login
- User action None No action by another user is required
- Vulnerable system: Data exposure High Sensitive data can be exposed with serious impact
- Vulnerable system: Data changes High Protected data can be changed with serious impact
- Vulnerable system: Service disruption High The service can stop or suffer serious disruption
- Other systems: Data exposure None No additional impact beyond the vulnerable system
- Other systems: Data changes None No additional impact beyond the vulnerable system
- Other systems: Service disruption None No additional impact beyond the vulnerable system
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Open in FIRST.org calculatorReferences
- github.com · v8.21.0 (tag) patch release notes vendor advisory
- github.com · GHSA-2w86-xfrc-g85r vendor advisory
- nvd.nist.gov · CVE-2026-71867 vdb entry us government resource
- github.com · PR #3692 GitHub Advisory vendor advisory
- github.com · commit 8ef1bfd GitHub Advisory vendor advisory
- cvefeed.io · CVE-2026-71867 third party advisory vdb entry
- osv.dev · CVE-2026-71867 vdb entry