Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Orval: Import-time RCE via schema property name -> computed-property-key injection in the zod client
Vulnerability Description
Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema property name is emitted into the generated zod.object({...}) schema without safe encoding. This permits attacker-controlled JavaScript to be evaluated when the generated zod schema module is imported, resulting in code execution in the developer, CI, test, or application environment. The affected code is packages/zod/src/index.ts and zod object-key generation. This issue is fixed in version 8.21.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
SQL命令中使用的特殊元素转义处理不恰当(SQL注入)
Vulnerability Title
orval-labs orval SQL注入漏洞
Vulnerability Description
orval-labs orval是orval-labs组织的一款服务器设备与网络产品。 orval-labs orval 8.21.0之前版本存在安全漏洞,该漏洞源于schema属性名中的双引号未安全编码,可能导致导入生成的zod schema模块时执行攻击者控制的JavaScript代码。
CVSS Information
N/A
Vulnerability Type
N/A