Summary
When Orval is configured with output.baseUrl.getBaseUrlFromSpecification: true, it bakes the spec's
servers[0].url into the generated request URL as a template literal without escaping the backtick. A
server URL containing a backtick closes the template literal and injects a concatenation expression
evaluated when the generated URL/request function is called, executing attacker-controlled code.
Verified on Orval 8.19.0 (fetch client); survives default OpenAPI validation.
Details
return `http://api.x/` + (globalThis.X = require("fs").writeFileSync("/marker","pwned")) + `/v1/u`;
Prerequisite: the documented getBaseUrlFromSpecification: true option (takes the base URL from the
OpenAPI servers block). This is the same output sink as the route-path case (request-URL template
literal) reached via the server url field. Distinct from Orval's published CVEs (CVE-2026-22785
summary/MCP, CVE-2026-23947 / CVE-2026-25141 x-enumDescriptions, CVE-2026-24132 const/mock).
PoC
reproduce.sh (+ make_spec.py) attached: generates a fetch client with
getBaseUrlFromSpecification: true, bundles it, calls the functions, and shows a marker written.
Verified on 8.19.0.
Impact
With that option enabled, code execution in any environment that calls a client generated from an
attacker-controlled or attacker-influenced OpenAPI description. Estimated Critical, e.g.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N (the CNA sets the final score; the config precondition
may lower it).
Suggested fix
Escape the server URL before emitting it into the URL template literal (escape backtick and ${), or
build the base URL with an encoder that treats it as data; validate the URL.
maintainer-report.txt
make_spec.py
reproduce.sh
Summary
When Orval is configured with
output.baseUrl.getBaseUrlFromSpecification: true, it bakes the spec'sservers[0].urlinto the generated request URL as a template literal without escaping the backtick. Aserver URL containing a backtick closes the template literal and injects a concatenation expression
evaluated when the generated URL/request function is called, executing attacker-controlled code.
Verified on Orval 8.19.0 (fetch client); survives default OpenAPI validation.
Details
Prerequisite: the documented
getBaseUrlFromSpecification: trueoption (takes the base URL from theOpenAPI servers block). This is the same output sink as the route-path case (request-URL template
literal) reached via the server
urlfield. Distinct from Orval's published CVEs (CVE-2026-22785summary/MCP, CVE-2026-23947 / CVE-2026-25141 x-enumDescriptions, CVE-2026-24132 const/mock).
PoC
reproduce.sh(+make_spec.py) attached: generates a fetch client withgetBaseUrlFromSpecification: true, bundles it, calls the functions, and shows a marker written.Verified on 8.19.0.
Impact
With that option enabled, code execution in any environment that calls a client generated from an
attacker-controlled or attacker-influenced OpenAPI description. Estimated Critical, e.g.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N(the CNA sets the final score; the config preconditionmay lower it).
Suggested fix
Escape the server URL before emitting it into the URL template literal (escape backtick and
${), orbuild the base URL with an encoder that treats it as data; validate the URL.
maintainer-report.txt
make_spec.py
reproduce.sh