NPM · SEPTEMBER 2026 · EARLY WARNING

Orval npm Package Vulnerability: Import-Time RCE via Schema Property Injection

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
orval (npm)
Affected versions
< 8.21.0 or < 8.22.0 or < 8.21.0
Patched version
Not yet available
GHSA-6MR6-JVCR-2F25

The orval npm package is reportedly vulnerable to import-time remote code execution due to schema property name injection. This issue is under investigation.

What happened

The vulnerability in orval allows for import-time remote code execution via schema property name injection. This occurs when generating a zod object without escaping double quotes in property names. The affected versions are those below 8.21.0, 8.22.0, and 8.21.0. The issue has been flagged but not yet confirmed as exploited in the wild.

To assess your exposure, check if your project uses orval and if so, which version. If you are using a version below the specified thresholds, you may be at risk. It is recommended to avoid using orval until a patched version is released or to ensure that schema property names do not contain double quotes if continued use is necessary.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If orval is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You may be affected if you are using orval npm package versions below 8.21.0, 8.22.0, or 8.21.0.

What should I do right now?

Avoid using orval until a patched version is released. If you must use orval, ensure that schema property names do not contain double quotes.

Is there an official fix available?

No official fix has been published yet. Monitor the primary sources for updates.

Sources

Join the 0Day waitlist →

← Back to all threats