THREAT OPS › Threat News › [GHSA] GHSA-6437-gxhq-pqv8 (critical) — Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
[GHSA] GHSA-6437-gxhq-pqv8 (critical) — Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
GHSA-6437-gxhq-pqv8 Severity: critical CVE: CVE-2026-71864
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
### Summary
orval's zod client emits each header parameter name as a double-quoted key in the generated zod.object({...}) request-validation schema WITHOUT escaping the double quote. A " in the header parameter name closes the key and l
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-71864cve
Original source: https://github.com/advisories/GHSA-6437-gxhq-pqv8