You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Package-init RCE via enum value -> const-block breakout -> injected func init()
Moderate
mromaszewicz
published
GHSA-xrqw-w576-xgj2Jul 7, 2026
oapi-codegen interpolates an enum string value unescaped into a Go interpreted-string constant in a
generated const (…) block (<Name> Color = "<value>"). A " in the value closes the string; a value
crafted to close the const block, inject a func init(), and reopen a const block produces valid Go
whose func init() runs at package initialization, executing attacker-controlled code. This escalates
the earlier build-corruption classification to confirmed RCE. Verified on oapi-codegen v2 / Go 1.25.
Note
A vulnerability like this requires that it is missed in code review and that you then call the malicious method.
Using an init() function could be enough to not require a direct call to the code, and instead rely on you importing the package, but either way, code review should be performed before any oapi-codegen generated code is executed.
We strongly recommend all users to be reviewing changes to their generated code before they execute anything within it, to protect against supply chain attacks or malicious injected code.
This is also why we recommend oapi-codegen generated code is committed to source control.
reproduce.sh (+ make_spec.py) attached: sets up a Go module, generates the types, adds a
same-package helper oapiPwn() (writes a marker), and runs a program that imports the package; the
marker is written during package init, before main. Verified on v2 / Go 1.25.
Impact
Code execution at package initialization in any application that compiles and runs oapi-codegen output
generated from an attacker-controlled or attacker-influenced spec. Estimated High, e.g. CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.
Suggested fix
Escape enum values (strconv.Quote/%q) before emitting them into the Go string constant, and/or
validate that enum values contain only legal characters. Never interpolate a spec string raw into
generated source. maintainer-report.txt make_spec.py reproduce.sh
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Learn more on MITRE.
The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
Learn more on MITRE.
Summary
oapi-codegen interpolates an enum string value unescaped into a Go interpreted-string constant in a
generated
const (…)block (<Name> Color = "<value>"). A"in the value closes the string; a valuecrafted to close the const block, inject a
func init(), and reopen a const block produces valid Gowhose
func init()runs at package initialization, executing attacker-controlled code. This escalatesthe earlier build-corruption classification to confirmed RCE. Verified on oapi-codegen v2 / Go 1.25.
Note
A vulnerability like this requires that it is missed in code review and that you then call the malicious method.
Using an
init()function could be enough to not require a direct call to the code, and instead rely on you importing the package, but either way, code review should be performed before anyoapi-codegengenerated code is executed.We strongly recommend all users to be reviewing changes to their generated code before they execute anything within it, to protect against supply chain attacks or malicious injected code.
This is also why we recommend
oapi-codegengenerated code is committed to source control.Details
Malicious enum value:
blue"; ); func init(){ oapiPwn() }; const ( Dummy Color = "x.PoC
reproduce.sh(+make_spec.py) attached: sets up a Go module, generates the types, adds asame-package helper
oapiPwn()(writes a marker), and runs a program that imports the package; themarker is written during package init, before
main. Verified on v2 / Go 1.25.Impact
Code execution at package initialization in any application that compiles and runs oapi-codegen output
generated from an attacker-controlled or attacker-influenced spec. Estimated High, e.g.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.Suggested fix
Escape enum values (
strconv.Quote/%q) before emitting them into the Go string constant, and/orvalidate that enum values contain only legal characters. Never interpolate a spec string raw into
generated source.
maintainer-report.txt
make_spec.py
reproduce.sh