Orval: Multiple RCE vulnerabilities in code generation
Three remote code execution vulnerabilities were discovered in Orval's OpenAPI schema generation affecting zod schemas, server URLs, and API paths. These vulnerabilities allow attackers to inject arbitrary code that executes during import or function calls.
Disclosed 3 September 2026 · Record updated 13 September 2026
Impact
Code execution in applications that import generated zod schemas or call client functions generated from attacker-controlled OpenAPI specifications.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-w727-8j6c-2rj4
- github.comhttps://github.com/advisories/GHSA-88f2-fpv8-89q2
- github.comhttps://github.com/advisories/GHSA-fg9p-mrxr-hvq7
