Description
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__ properties in packages/respect-core/src/modules/context-parser/get-value-from-context.ts, reach the JavaScript Function constructor, and execute arbitrary code when a user processes an untrusted description. The executed code runs with the privileges of the CLI process and can execute shell commands or read CI secrets. Users processing only trusted, self-authored workflows are not affected. This issue is fixed in @redocly/respect-core and @redocly/cli version 2.33.0.
Published: 2026-09-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Redocly CLI stems from the dynamic evaluation of $faker expressions within Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__ properties, reach the JavaScript Function constructor, and execute arbitrary code. Executed code runs with the privileges of the CLI process, allowing shell commands or reading CI secrets, which is a classic code injection issue (CWE‑94) and an improper handling of dynamic code (CWE‑95).

Affected Systems

Redocly CLI and its @redocly/respect-core dependency before version 2.33.0 are affected. Any environment running the CLI that processes untrusted OpenAPI or Arazzo files can be compromised, including local development workstations and CI/CD pipelines that import external descriptions. The flaw does not affect users who only process trusted, self‑authored workflows.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑impact flaw. The EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. An attacker can exploit the bug by supplying a malicious description to any instance of the CLI that evaluates untrusted input, potentially during offline builds or via a compromised source file. The attack does not require a network connection once the malicious file is introduced, making it viable in isolated or internal environments.

Generated by OpenCVE AI on September 18, 2026 at 00:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Redocly CLI and the @redocly/respect-core package to version 2.33.0 or later, which disables unsafe dynamic evaluation of $faker expressions.
  • Verify that all OpenAPI/Arazzo descriptions used in CI or local workflows originate from trusted, verified sources and enforce whitelist checks to block unexpected $faker expressions.
  • If an immediate upgrade is not possible, temporarily disable or remove the respect command, or configure it to skip dynamic evaluation of $faker expressions, until a patch is applied.

Generated by OpenCVE AI on September 18, 2026 at 00:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Redocly
Redocly redoc
Vendors & Products Redocly
Redocly redoc

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__ properties in packages/respect-core/src/modules/context-parser/get-value-from-context.ts, reach the JavaScript Function constructor, and execute arbitrary code when a user processes an untrusted description. The executed code runs with the privileges of the CLI process and can execute shell commands or read CI secrets. Users processing only trusted, self-authored workflows are not affected. This issue is fixed in @redocly/respect-core and @redocly/cli version 2.33.0.
Title Redocly CLI: Arbitrary code execution via Arazzo `$faker` expression using `respect`
Weaknesses CWE-94
CWE-95
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T18:23:39.395Z

Reserved: 2026-07-16T14:14:24.384Z

Link: CVE-2026-63325

cve-icon Vulnrichment

Updated: 2026-09-18T18:23:35.313Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T19:17:24.317

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-63325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:45:14Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')

  • CWE-95

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')