THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6437-gxhq-pqv8 (critical) — Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client

[GHSA] GHSA-6437-gxhq-pqv8 (critical) — Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client

medgithub_advisoriesPublished 2026-09-03

GHSA-6437-gxhq-pqv8 Severity: critical CVE: CVE-2026-71864

Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client

### Summary

orval's zod client emits each header parameter name as a double-quoted key in the generated zod.object({...}) request-validation schema WITHOUT escaping the double quote. A " in the header parameter name closes the key and l

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6437-gxhq-pqv8