Impact
The Redocly CLI allows an attacker to influence file paths used in its split command by providing component names or x‑codeSamples language values containing literal ../ traversal fragments. Because the CLI does not validate that the resolved target remains inside the user‑supplied –outDir directory, the attacker can cause the command to write or overwrite files outside that directory. Although the data written is limited to YAML/JSON for components and method‑based filenames for code samples, the possibility of corrupting or replacing arbitrary files can still impact integrity and availability of the host system. The CVSS score of 4.4 reflects a medium severity resulting from the constrained nature of the payload, and the EPSS indicates that exploitation likelihood is very low; the vulnerability is not listed in CISA KEV.
Affected Systems
Redocly CLI, any release prior to 2.33.2, is affected. Users running earlier releases must upgrade to 2.33.2 or later to remediate the path traversal flaw.
Risk and Exploitability
The vulnerability can be exploited when an attacker supplies a crafted OpenAPI or AsyncAPI specification containing component names or x‑codeSamples lang values that include traversal sequences. Running the split command against a selected output directory then allows creation or overwrite of files outside that directory. The required step is local execution of the CLI with the malicious spec, so the attack vector is local but could be remote if the CLI processes user‑supplied specs in an automated environment. The low EPSS (<1%) suggests real‑world exploitation is unlikely at present, and the non‑listing in the KEV catalog confirms this. Prompt patching remains recommended to avoid filesystem integrity risks.
OpenCVE Enrichment
Github GHSA