THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-653q-5476-x79g (critical) — Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli

[GHSA] GHSA-653q-5476-x79g (critical) — Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli

medgithub_advisoriesPublished 2026-09-03

GHSA-653q-5476-x79g Severity: critical CVE: CVE-2026-71865

Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli

### Summary

orval's zod client emits each query parameter name as a double-quoted key in the generated zod.object({...}) request-validation schema WITHOUT escaping the double quote. A " in the query parameter name closes the key and lands i

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-653q-5476-x79g