Description
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSamples lang values without verifying that the resolved target remains inside the selected directory. A description containing literal ../ traversal segments in those fields can cause the split command to place or overwrite files outside --outDir. Component data remains constrained to YAML or JSON, and code-sample filenames remain based on the HTTP method, so this is not an unrestricted arbitrary-content file write. This issue is fixed in @redocly/cli version 2.33.2.
Published: 2026-09-16
Score: 4.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: File path traversal, potential overwrite outside intended directory
Action: Apply patch
AI Analysis

Impact

The Redocly CLI allows an attacker to influence file paths used in its split command by providing component names or x‑codeSamples language values containing literal ../ traversal fragments. Because the CLI does not validate that the resolved target remains inside the user‑supplied –outDir directory, the attacker can cause the command to write or overwrite files outside that directory. Although the data written is limited to YAML/JSON for components and method‑based filenames for code samples, the possibility of corrupting or replacing arbitrary files can still impact integrity and availability of the host system. The CVSS score of 4.4 reflects a medium severity resulting from the constrained nature of the payload, and the EPSS indicates that exploitation likelihood is very low; the vulnerability is not listed in CISA KEV.

Affected Systems

Redocly CLI, any release prior to 2.33.2, is affected. Users running earlier releases must upgrade to 2.33.2 or later to remediate the path traversal flaw.

Risk and Exploitability

The vulnerability can be exploited when an attacker supplies a crafted OpenAPI or AsyncAPI specification containing component names or x‑codeSamples lang values that include traversal sequences. Running the split command against a selected output directory then allows creation or overwrite of files outside that directory. The required step is local execution of the CLI with the malicious spec, so the attack vector is local but could be remote if the CLI processes user‑supplied specs in an automated environment. The low EPSS (<1%) suggests real‑world exploitation is unlikely at present, and the non‑listing in the KEV catalog confirms this. Prompt patching remains recommended to avoid filesystem integrity risks.

Generated by OpenCVE AI on September 18, 2026 at 00:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Redocly CLI to 2.33.2 or later where the path traversal issue is fixed.
  • Validate or sanitize component names and x‑codeSamples lang values to eliminate '../' sequences before they are passed to the split command.
  • Configure the --outDir option to point to a directory with appropriate permissions and restrict write access to avoid accidental overwrites.

Generated by OpenCVE AI on September 18, 2026 at 00:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-657c-g7qc-r9j2 Redocly CLI: Path traversal when using `split` command
History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Redocly
Redocly redoc
Vendors & Products Redocly
Redocly redoc

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSamples lang values without verifying that the resolved target remains inside the selected directory. A description containing literal ../ traversal segments in those fields can cause the split command to place or overwrite files outside --outDir. Component data remains constrained to YAML or JSON, and code-sample filenames remain based on the HTTP method, so this is not an unrestricted arbitrary-content file write. This issue is fixed in @redocly/cli version 2.33.2.
Title Redocly CLI: Path traversal when using `split` command
Weaknesses CWE-22
CWE-73
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T16:13:49.405Z

Reserved: 2026-07-15T22:19:06.907Z

Link: CVE-2026-63225

cve-icon Vulnrichment

Updated: 2026-09-17T16:13:44.635Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T19:17:24.163

Modified: 2026-09-30T17:51:36.337

Link: CVE-2026-63225

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:45:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path