PT-2026-78544 · Orval · Orval
CVE-2026-62680
·
Published
2026-08-19
·
Updated
2026-09-03
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Orval versions prior to 8.22.0
Description
Orval resolves remote and local external
$ref values without an allowlist or confinement to the input directory. Processing an attacker-controlled OpenAPI description can lead to requests from the developer or CI host to attacker-selected or internal HTTP services, the reading of absolute or out-of-tree local files, and the inlining of untrusted remote schemas into generated clients. The issue resides in the external reference loading within packages/orval/src/import-specs.ts.Recommendations
Update to version 8.22.0.
Exploit
Fix
Path traversal
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Orval