THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cxq5-97v7-87j8 (high) — Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

[GHSA] GHSA-cxq5-97v7-87j8 (high) — Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

highgithub_advisoriesPublished 2026-09-02

GHSA-cxq5-97v7-87j8 Severity: high CVE: CVE-2026-62680

Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

### Summary

Orval resolves OpenAPI `$ref`s by fetching remote `http(s)` URLs and reading local files (including absolute / out-of-tree paths), inlining the referenced schema into the generated client. Running `orval` on a spec whose `$ref` points at an attacker/

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cxq5-97v7-87j8