A AegiFlow
MEDIUMCVSS 4.4EPSS 0.2%

CVE-2026-63225

CVE-2026-63225 updated by NVD

Published
2026-09-17
Modified
2026-09-19
EPSS percentile
7%
Sources
github-advisory, nvd

Summary

Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSamples lang values without verifying that the resolved target remains inside the selected directory. A description containing literal ../ traversal segments in those fields can cause the split command to place or overwrite files outside --outDir. Component data remains constrained to YAML or JSON, and code-sample filenames remain based on the HTTP method, so this is not an unrestricted arbitrary-content file write. This issue is fixed in @redocly/cli version 2.33.2.

Affected packages

EcosystemPackageAffected versionsFixed versions
npm@redocly/cli1.34.17, 2.33.2

Remediation: Upgrade to 1.34.17 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.