{"id":"CVE-2026-62680","aliases":["GHSA-cxq5-97v7-87j8"],"url":"https://o3.security/vulnerability/CVE-2026-62680","summary":"Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref","details":"### Summary\n\nOrval resolves OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files (including\nabsolute / out-of-tree paths), inlining the referenced schema into the generated client. Running\n`orval` on a spec whose `$ref` points at an attacker/internal URL or an arbitrary local file yields\nSSRF, remote file inclusion, and local file inclusion. Verified on 8.19.0. This is a different class\nfrom Orval's published output-injection CVEs (CVE-2026-22785/23947/24132/25141), none of which covers\nthe `$ref` resolver.\n\n### Details\n\n- `$ref: http://attacker/internal-evil.json#/...` → build host fetches (SSRF) and inlines the remote\n  schema (RFI); confirmed property `REMOTE_ORVAL_PROP` in the generated client.\n- `$ref: /abs/path.json#/...` or `../../secret.json#/...` → out-of-tree local file read + inlined (LFI).\n\nNo RCE: on 8.19.0 the description JSDoc is escaped (`*/`->`*\\/`, the published fix), so `$ref` content\ncannot break out into code. The chain stops at SSRF + RFI + LFI.\n\nFix: don't resolve remote `$ref`s by default (opt-in + host allowlist); confine local `$ref`\nresolution to the input directory tree (reject absolute paths and `../` escapes).\n\n### PoC\n\n`reproduce.sh` attached: confirms LFI (out-of-tree read), SSRF (listener hit), RFI (remote schema\ninlined). Verified on Orval 8.19.0.\n\n### Impact\n\nBuild-time SSRF from the developer or CI host, disclosure of arbitrary local files, and inclusion of untrusted remote content, from running the generator on an attacker-controlled or attacker-influenced OpenAPI description. No code execution (output escaping is in place post the earlier fixes).","published":"2026-08-19T17:42:11.227Z","modified":"2026-09-11T03:30:37.876040454Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N"},"epss":{"score":0.00309,"percentile":0.23366,"asOf":"2026-09-07"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"orval","fixedVersion":"8.22.0"}],"fix":{"url":"https://github.com/orval-labs/orval/commit/23786c056f4eba38c02bf2968677988dbbe4de10","label":"orval-labs/orval@23786c0"},"references":[{"type":"WEB","url":"https://github.com/orval-labs/orval/releases/tag/v8.22.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62680.json"},{"type":"ADVISORY","url":"https://github.com/orval-labs/orval/security/advisories/GHSA-cxq5-97v7-87j8"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62680"},{"type":"FIX","url":"https://github.com/orval-labs/orval/commit/23786c056f4eba38c02bf2968677988dbbe4de10"},{"type":"FIX","url":"https://github.com/orval-labs/orval/pull/3723"},{"type":"WEB","url":"https://github.com/orval-labs/orval/pull/3692"},{"type":"WEB","url":"https://github.com/orval-labs/orval/commit/8ef1bfdf3f9bcaf9dabfbe2e42887f1c0e159ab6"},{"type":"PACKAGE","url":"https://github.com/orval-labs/orval"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-11T03:30:37.876040454Z"}}