CVE-2026-62680
### Summary Orval resolves OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files (including absolute / out-of-tree paths), inlining the referenced schema into the generated client. Running `orval` on a spec whose `$ref` points at an attacker/internal URL or an arbitrary local file yields SSRF, remote file inclusion, and local file inclusion. Verified on 8.19.0. This is a different class from Orval's published output-injection CVEs (CVE-2026-22785/23947/24132/25141), none of which covers the `$ref` resolver. ### Details - `$ref: http://attacker/internal-evil.json#/...` → build host fetches (SSRF) and inlines the remote schema (RFI); confirmed property `REMOTE_ORVAL_PROP` in the generated client. - `$ref: /abs/path.json#/...` or `../../secret.json#/...` → out-of-tree local file read + inlined (LFI). No RCE: on 8.19.0 the description JSDoc is escaped (`*/`->`*\/`, the published fix), so `$ref` content cannot break out into code. The chain stops at SSRF + RFI + LFI. Fix: don't resolve remote `$ref`s by default (opt-in + host allowlist); confine local `$ref` resolution to the input directory tree (reject absolute paths and `../` escapes). ### PoC `reproduce.sh` attached: confirms LFI (out-of-tree read), SSRF (listener hit), RFI (remote schema inlined). Verified on Orval 8.19.0. ### Impact Build-time SSRF from the developer or CI host, disclosure of arbitrary local files, and inclusion of untrusted remote content, from running the generator on an attacker-controlled or attacker-influenced OpenAPI description. No code execution (output escaping is in place post the earlier fixes).
Properties
- ghsa_id
- GHSA-cxq5-97v7-87j8
- severity
- high
- summary
- Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
- cvss_score
- 7.1
- cve_id
- CVE-2026-62680
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
- is_ghsa_only
- false
- ghsa_published
- 2026-09-02T14:54:48Z
- source_url
- https://github.com/advisories/GHSA-cxq5-97v7-87j8
- ghsa_updated
- 2026-09-02T14:54:50Z
Related Entities (6)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (3)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph