OSV 1.4.0 · github-reviewed · 修改于 2026-09-02 22:54
发布时间
2026-09-02 22:54
GitHub 审查时间
2026-09-02 22:54
NVD 发布时间
2026-08-20 02:16
源文件
advisories/github-reviewed/2026/09/GHSA-cxq5-97v7-87j8/GHSA-cxq5-97v7-87j8.json
Orval resolves OpenAPI $refs by fetching remote http(s) URLs and reading local files (including
absolute / out-of-tree paths), inlining the referenced schema into the generated client. Running
orval on a spec whose $ref points at an attacker/internal URL or an arbitrary local file yields
SSRF, remote file inclusion, and local file inclusion. Verified on 8.19.0. This is a different class
from Orval's published output-injection CVEs (CVE-2026-22785/23947/24132/25141), none of which covers
the $ref resolver.
$ref: http://attacker/internal-evil.json#/... → build host fetches (SSRF) and inlines the remote
schema (RFI); confirmed property REMOTE_ORVAL_PROP in the generated client.$ref: /abs/path.json#/... or ../../secret.json#/... → out-of-tree local file read + inlined (LFI).No RCE: on 8.19.0 the description JSDoc is escaped (*/->*\/, the published fix), so $ref content
cannot break out into code. The chain stops at SSRF + RFI + LFI.
Fix: don't resolve remote $refs by default (opt-in + host allowlist); confine local $ref
resolution to the input directory tree (reject absolute paths and ../ escapes).
reproduce.sh attached: confirms LFI (out-of-tree read), SSRF (listener hit), RFI (remote schema
inlined). Verified on Orval 8.19.0.
Build-time SSRF from the developer or CI host, disclosure of arbitrary local files, and inclusion of untrusted remote content, from running the generator on an attacker-controlled or attacker-influenced OpenAPI description. No code execution (output escaping is in place post the earlier fixes).