CyberRota Analysis
AI-GeneratedThe vulnerability affects the Orval tool used for generating type-safe JavaScript clients from OpenAPI specifications, specifically in versions prior to 8.21.0. An unsafe encoding flaw allows attacker-controlled JavaScript to be executed upon importing the generated zod schema module, leading to potential code execution in various environments, including development and CI. Organizations utilizing Orval for JavaScript client generation should prioritize upgrading to version 8.21.0 to mitigate this critical risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template literal emitted by zod schema generation without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts function formatDefaultValue. This issue is fixed in version 8.21.0.