Orval bug lets a spec file run attacker code
Orval is a developer tool that turns API specification files into ready-to-use code. A booby-trapped spec file can make Orval run the attacker's own JavaScript the moment a developer or build system opens the generated code.
- Severity
- CriticalCVSS 4.0 · 9.3
- Fix
- Fixed in 8.21.0Fix recorded on Sep 3, 2026
- Affected versions
- before 8.21.0
- Weakness
- CWE-94Code Injection
- Exploit likelihood
- 0.66% in 30 daysEPSS, higher than 50% of known flaws
- Affects
- Orval+1 more
How it works
Orval writes a schema's default value straight into the generated code as raw text instead of treating it as plain data, so a specially crafted default value containing certain symbols becomes live JavaScript that runs the instant that generated file is loaded.
What to do
Run npm ls orval in your project to see the installed version, or check package.json and package-lock.json; anything before 8.21.0 is vulnerable. Update to Orval 8.21.0 or later with npm install orval@8.21.0, and treat any OpenAPI spec from an untrusted source as unsafe to run through older Orval versions until you upgrade.
Run this in the application environment you want to check:
npm ls orvalTechnical details
Affected software: Orval, npm
Orval's zod schema generator writes a schema's default value into a module-level template literal without escaping backticks or ${...} sequences. A default value like v${globalThis.someFunction}w becomes a live JavaScript expression in the generated file, so the attacker's code executes at import time, in whatever environment loads that file (developer machine, CI runner, test suite, or application). No function call or network request is needed, just importing the generated module.
The bug is in packages/zod/src/index.ts, function formatDefaultValue, and was verified against Orval 8.19.0. It is fixed in 8.21.0.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low No extra steps to bypass built-in attack protections
- Required conditions None No particular deployment or execution condition is required
- Privileges required None Attacker needs no account or login
- User action None No action by another user is required
- Vulnerable system: Data exposure High Sensitive data can be exposed with serious impact
- Vulnerable system: Data changes High Protected data can be changed with serious impact
- Vulnerable system: Service disruption High The service can stop or suffer serious disruption
- Other systems: Data exposure None No additional impact beyond the vulnerable system
- Other systems: Data changes None No additional impact beyond the vulnerable system
- Other systems: Service disruption None No additional impact beyond the vulnerable system
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Open in FIRST.org calculatorReferences
- github.com · v8.21.0 (tag) patch release notes vendor advisory
- github.com · GHSA-w727-8j6c-2rj4 vendor advisory
- nvd.nist.gov · CVE-2026-72717 vdb entry us government resource
- github.com · PR #3692 GitHub Advisory vendor advisory
- github.com · commit 8ef1bfd GitHub Advisory vendor advisory
- tenable.com · CVE-2026-72717 third party advisory vdb entry
- cvefeed.io · CVE-2026-72717 third party advisory vdb entry
- osv.dev · CVE-2026-72717 vdb entry