{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aorvalorval/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:orval:orval:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-72716"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Orval (\u003c 8.21.0)"],"_cs_severities":["critical"],"_cs_tags":["supply-chain","rce","nodejs","typescript"],"_cs_type":"advisory","_cs_vendors":["Orval"],"content_html":"\u003cp\u003eOrval, a popular tool for generating TypeScript clients and Zod schemas from OpenAPI specifications, contains a critical vulnerability (CVE-2026-72716) that allows for remote code execution. The issue stems from the way the tool emits query parameter default values within the generated Zod schema modules. Specifically, these values are written as module-level template literals (e.g., \u003ccode\u003eexport const …Default = \u003c/code\u003e\u0026lt;default\u0026gt;\u003ccode\u003e;\u003c/code\u003e) without adequate escaping of backticks or the \u003ccode\u003e${\u003c/code\u003e character sequence.\u003c/p\u003e\n\u003cp\u003eAn attacker who can provide or influence an OpenAPI specification can include a crafted default value containing a JavaScript expression, such as \u003ccode\u003ev${\u0026lt;attacker-controlled-JS\u0026gt;}w\u003c/code\u003e. When an application imports the generated Zod schema module, the JavaScript engine evaluates the interpolated expression, leading to arbitrary code execution within the context of the importing process. This vulnerability is present in Orval version 8.19.0 and affects all versions prior to 8.21.0. The exploit requires no additional API interaction once the malicious schema is generated and integrated into the victim's codebase.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in arbitrary code execution during the build or runtime import phase of any application relying on Orval-generated schemas. This poses a significant risk to CI/CD pipelines, build servers, and runtime environments that process untrusted OpenAPI descriptions. The scope includes any application that integrates Orval to generate schemas from attacker-influenced input sources, such as public repositories or user-submitted API documentation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Orval to version 8.21.0 or later immediately to resolve CVE-2026-72716.\u003c/li\u003e\n\u003cli\u003eAudit existing OpenAPI specifications used in build processes to ensure \u003ccode\u003edefault\u003c/code\u003e values do not contain suspicious syntax like \u003ccode\u003e${\u003c/code\u003e or backticks.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, implement strict validation of OpenAPI specification files before feeding them into the Orval generator.\u003c/li\u003e\n\u003cli\u003eReview build pipeline logs for unexpected execution of JavaScript modules generated by Orval.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T18:03:14Z","date_published":"2026-09-02T18:03:05Z","id":"https://feed.craftedsignal.io/briefs/2026-09-orval-rce/","summary":"Orval versions prior to 8.21.0 are vulnerable to remote code execution during module import due to improper sanitization of OpenAPI query parameter default values in generated Zod schemas.","title":"Remote Code Execution in Orval via Malicious Zod Schema Generation","url":"https://feed.craftedsignal.io/briefs/2026-09-orval-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:orval:orval:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}