Skip to content

[audit] critical: CVE-2026-62682 in orval@8.5.3 #40

Description

@github-actions

Severity: critical
CVE: CVE-2026-62682
Package: orval @ 8.5.3
Vulnerable range: <8.21.0
Patched in: >=8.21.0
Dep paths:

  • lib__api-spec>orval

Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)

Reference: GHSA-88f2-fpv8-89q2
Filed automatically by .github/workflows/pnpm-audit.yml. The fix
work for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md §11 limitation 4 for the
policy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to scripts/audit/ignore-list.json
with a written reachability rationale and a re-evaluation date.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    audit:cveAutomated pnpm audit finding

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions