Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a code injection vulnerability identified in a development tool that generates client code from OpenAPI schemas. The flaw allows specially crafted schema property names to execute arbitrary code with consumer process privileges during the client build, potentially impacting the integrity of the generated code. The main concern is confirming relevance and exposure to our development workflows.
- Vulnerability allows code injection during client code generation.
- Affects developer tools, not deployed applications directly.
- Confirm if this tool is used in our development process.
Attack Path
How an attacker could exploit the issue
Attackers could inject malicious code into the property names of form data. This occurs when the code generation tool processes OpenAPI schema definitions and fails to properly escape special characters in property names. If these names are later used in a client application that builds form data, the injected code can execute with the privileges of the application that consumes the data.
- No specific user interaction needed.
- Vulnerability triggered by code generation process.
- Risk of arbitrary code execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow attackers to inject code into generated client applications. This code could execute with the privileges of the consumer process when the client builds FormData bodies, potentially affecting service behavior.
- Executed code with consumer privileges.
- Code injection via form-data serialization.
- Compromise of consumer process.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability affects the form-data serializer in the @orval/core tool, which is used during the development or CI/CD build process. Ownership will likely fall to development teams or platform engineers responsible for the build tooling and generated client code. The first practical step is to confirm the specific usage and scope of @orval/core within the development lifecycle, identify which projects generate client code, and assess the risk associated with any affected property names.
- Development or platform teams own resolution.
- Verify @orval/core build-time usage.
- Plan code generation updates.