Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 19 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Orval-labs
Orval-labs orval |
|
| Vendors & Products |
Orval-labs
Orval-labs orval |
Wed, 19 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. Processing an attacker-controlled OpenAPI description can cause requests from the developer or CI host to attacker-selected or internal HTTP services, read absolute or out-of-tree local files, and inline untrusted remote schemas into generated clients. The affected code is packages/orval/src/import-specs.ts external reference loading. This issue is fixed in version 8.22.0. | |
| Title | Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref | |
| Weaknesses | CWE-22 CWE-829 CWE-918 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-19T18:06:47.948Z
Reserved: 2026-07-14T20:22:04.395Z
Link: CVE-2026-62680
No data.
Status : Received
Published: 2026-08-19T18:16:54.230
Modified: 2026-08-19T18:16:54.230
Link: CVE-2026-62680
No data.
OpenCVE Enrichment
Updated: 2026-08-19T19:45:03Z