Skip to content

Package-init RCE via enum value -> const-block breakout -> injected func init()

Moderate
mromaszewicz published GHSA-xrqw-w576-xgj2 Jul 7, 2026

Package

gomod github.com/oapi-codegen/oapi-codegen/v2 (Go)

Affected versions

v2.7.1

Patched versions

None

Description

Summary

oapi-codegen interpolates an enum string value unescaped into a Go interpreted-string constant in a
generated const (…) block (<Name> Color = "<value>"). A " in the value closes the string; a value
crafted to close the const block, inject a func init(), and reopen a const block produces valid Go
whose func init() runs at package initialization, executing attacker-controlled code. This escalates
the earlier build-corruption classification to confirmed RCE. Verified on oapi-codegen v2 / Go 1.25.

Note

A vulnerability like this requires that it is missed in code review and that you then call the malicious method.

Using an init() function could be enough to not require a direct call to the code, and instead rely on you importing the package, but either way, code review should be performed before any oapi-codegen generated code is executed.

We strongly recommend all users to be reviewing changes to their generated code before they execute anything within it, to protect against supply chain attacks or malicious injected code.

This is also why we recommend oapi-codegen generated code is committed to source control.

Details

const ( BlueFuncInitOapiPwnConstDummyColorx Color = "blue" )
func init() { oapiPwn() }        // injected; runs at package init
const ( Dummy Color = "x" )

Malicious enum value: blue"; ); func init(){ oapiPwn() }; const ( Dummy Color = "x.

PoC

reproduce.sh (+ make_spec.py) attached: sets up a Go module, generates the types, adds a
same-package helper oapiPwn() (writes a marker), and runs a program that imports the package; the
marker is written during package init, before main. Verified on v2 / Go 1.25.

Impact

Code execution at package initialization in any application that compiles and runs oapi-codegen output
generated from an attacker-controlled or attacker-influenced spec. Estimated High, e.g.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

Suggested fix

Escape enum values (strconv.Quote/%q) before emitting them into the Go string constant, and/or
validate that enum values contain only legal characters. Never interpolate a spec string raw into
generated source.
maintainer-report.txt
make_spec.py
reproduce.sh

Severity

Moderate

CVSS overall score

This score calculates overall vulnerability severity from 0 to 10 and is based on the Common Vulnerability Scoring System (CVSS).
/ 10

CVSS v3 base metrics

Attack vector
Local
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low

CVSS v3 base metrics

Attack vector: More severe the more the remote (logically and physically) an attacker can be in order to exploit the vulnerability.
Attack complexity: More severe for the least complex attacks.
Privileges required: More severe if no privileges are required.
User interaction: More severe when no user interaction is required.
Scope: More severe when a scope change occurs, e.g. one vulnerable component impacts resources in components beyond its security scope.
Confidentiality: More severe when loss of data confidentiality is highest, measuring the level of data access available to an unauthorized user.
Integrity: More severe when loss of data integrity is the highest, measuring the consequence of data modification possible by an unauthorized user.
Availability: More severe when the loss of impacted component availability is highest.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

CVE ID

No known CVE

Weaknesses

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment. Learn more on MITRE.

Improper Encoding or Escaping of Output

The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved. Learn more on MITRE.

Credits