CVE-2026-62680 is a high-severity (CVSS 7.1) Path Traversal vulnerability in orval. A fix is available for orval — see the affected versions and patch details below.
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2026-62680 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 382,574 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, and reverse-dependency count shows how many other packages break if it stays unpatched.
orvalnpmDescription
Summary
Orval resolves OpenAPI $refs by fetching remote http(s) URLs and reading local files (including
absolute / out-of-tree paths), inlining the referenced schema into the generated client. Running
orval on a spec whose $ref points at an attacker/internal URL or an arbitrary local file yields
SSRF, remote file inclusion, and local file inclusion. Verified on 8.19.0. This is a different class
from Orval's published output-injection CVEs (CVE-2026-22785/23947/24132/25141), none of which covers
the $ref resolver.
Details
$ref: http://attacker/internal-evil.json#/...→ build host fetches (SSRF) and inlines the remote schema (RFI); confirmed propertyREMOTE_ORVAL_PROPin the generated client.$ref: /abs/path.json#/...or../../secret.json#/...→ out-of-tree local file read + inlined (LFI).
No RCE: on 8.19.0 the description JSDoc is escaped (*/->*\/, the published fix), so $ref content
cannot break out into code. The chain stops at SSRF + RFI + LFI.
Fix: don't resolve remote $refs by default (opt-in + host allowlist); confine local $ref
resolution to the input directory tree (reject absolute paths and ../ escapes).
PoC
reproduce.sh attached: confirms LFI (out-of-tree read), SSRF (listener hit), RFI (remote schema
inlined). Verified on Orval 8.19.0.
Impact
Build-time SSRF from the developer or CI host, disclosure of arbitrary local files, and inclusion of untrusted remote content, from running the generator on an attacker-controlled or attacker-influenced OpenAPI description. No code execution (output escaping is in place post the earlier fixes).
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | orval | all versions | 8.22.0npm install orval@8.22.0 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for orval, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update orval to 8.22.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2026-62680 is resolved across your whole dependency graph.
Workarounds
Resolve every user-supplied path to its canonical form and reject anything that escapes the intended directory, and run the component under an account that has no read or write access outside the directory it legitimately serves.
Frequently Asked Questions
Is CVE-2026-62680 in your dependencies?
Find it across npm, including transitive dependencies.