THREAT OPS › Threat News › [GHSA] GHSA-cxq5-97v7-87j8 (high) — Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
[GHSA] GHSA-cxq5-97v7-87j8 (high) — Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
GHSA-cxq5-97v7-87j8 Severity: high CVE: CVE-2026-62680
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
### Summary
Orval resolves OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files (including absolute / out-of-tree paths), inlining the referenced schema into the generated client. Running `orval` on a spec whose `$ref` points at an attacker/
Indicators of compromise
- CVE-2026-62680cve
- CVE-2026-22785cve
- http://attacker/internal-evil.json#/...`url
Original source: https://github.com/advisories/GHSA-cxq5-97v7-87j8