Impact
The vulnerability in Redocly CLI stems from the dynamic evaluation of $faker expressions within Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__ properties, reach the JavaScript Function constructor, and execute arbitrary code. Executed code runs with the privileges of the CLI process, allowing shell commands or reading CI secrets, which is a classic code injection issue (CWE‑94) and an improper handling of dynamic code (CWE‑95).
Affected Systems
Redocly CLI and its @redocly/respect-core dependency before version 2.33.0 are affected. Any environment running the CLI that processes untrusted OpenAPI or Arazzo files can be compromised, including local development workstations and CI/CD pipelines that import external descriptions. The flaw does not affect users who only process trusted, self‑authored workflows.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑impact flaw. The EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the bug by supplying a malicious description to any instance of the CLI that evaluates untrusted input, potentially during offline builds or via a compromised source file. The attack does not require a network connection once the malicious file is introduced, making it viable in isolated or internal environments.
OpenCVE Enrichment