CyberRota Analysis
AI-GeneratedVersions 8.19.0 to 8.21.0 of Orval, which generates type-safe JavaScript clients from OpenAPI specifications, contain a critical vulnerability that allows a double quote in a schema property name to be improperly encoded. This flaw enables the execution of attacker-controlled JavaScript when the generated zod schema module is imported, potentially compromising developer, CI, test, or application environments. Organizations using affected versions should prioritize upgrading to version 8.21.0 or later to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema property name is emitted into the generated zod.object({...}) schema without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts and zod object-key generation. This issue is fixed in version 8.21.0.