{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/orval--8.22.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-62680"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Orval (\u003c 8.22.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","ssrf","file-inclusion","supply-chain"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eOrval versions prior to 8.22.0 are susceptible to an information disclosure and SSRF vulnerability due to insecure handling of \u003ccode\u003e$ref\u003c/code\u003e pointers within OpenAPI specifications. During the generation process, Orval fetches remote HTTP(S) resources and reads arbitrary local files (including out-of-tree and absolute paths) to inline schema components. An attacker who provides a malicious OpenAPI specification can force the build host (developer machine or CI/CD environment) to perform unauthorized network requests or read sensitive files from the local filesystem.\u003c/p\u003e\n\u003cp\u003eWhile previous vulnerabilities in Orval allowed for output injection (RCE), the current implementation includes escaping for JSDoc descriptions, mitigating the risk of code execution. However, the ability to read arbitrary files and include remote schemas remains, leading to potential credential or configuration leakage from the build environment. The vendor has released a fix in version 8.22.0, which restricts \u003ccode\u003e$ref\u003c/code\u003e resolution to the local directory tree and disables remote resolution by default, requiring an opt-in allowlist.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in build-time SSRF, unauthorized disclosure of sensitive local files, and inclusion of untrusted remote content into generated client code. This impacts development environments and automated CI/CD pipelines, potentially exposing secrets, environment variables, or private source code to unauthorized parties or internal infrastructure if accessed via SSRF.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Orval to version 8.22.0 or later across all development and CI/CD environments.\u003c/li\u003e\n\u003cli\u003eAudit existing OpenAPI specifications used in build processes to ensure \u003ccode\u003e$ref\u003c/code\u003e fields point only to trusted, local sources within the project tree.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering for CI/CD build agents to prevent unexpected outbound connections initiated by build tools like Orval.\u003c/li\u003e\n\u003cli\u003eReview build logs for anomalous HTTP requests or unexpected file access patterns originating from the \u003ccode\u003eorval\u003c/code\u003e process.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T18:04:00Z","date_published":"2026-09-02T18:04:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-orval-ref-vulnerability/","summary":"Orval versions prior to 8.22.0 contain a vulnerability in the OpenAPI $ref resolver allowing build-time SSRF, remote file inclusion, and local file inclusion via crafted specification files.","title":"Orval OpenAPI $ref Resolver SSRF and File Inclusion","url":"https://feed.craftedsignal.io/briefs/2026-09-orval-ref-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Orval (\u003c 8.22.0)","version":"https://jsonfeed.org/version/1.1"}