PT-2026-78544 · Orval · Orval

CVE-2026-62680

·

Published

2026-08-19

·

Updated

2026-09-03

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Orval versions prior to 8.22.0
Description Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. Processing an attacker-controlled OpenAPI description can lead to requests from the developer or CI host to attacker-selected or internal HTTP services, the reading of absolute or out-of-tree local files, and the inlining of untrusted remote schemas into generated clients. The issue resides in the external reference loading within packages/orval/src/import-specs.ts.
Recommendations Update to version 8.22.0.

Exploit

Fix

Path traversal

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62680
GHSA-CXQ5-97V7-87J8

Affected Products

Orval