Redocly CLI: Path traversal when using `split` command
GHSA-657c-g7qc-r9j2 · CVE-2026-63225
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
An OpenAPI or AsyncAPI description could make the split command write
files outside the chosen output directory, on the machine of anyone who runssplit against it. The write is constrained rather than a free file-write
primitive: component data is emitted only as YAML/JSON, and code-sample files are
named after the HTTP method, so an attacker can place or overwrite files at an
unintended path but has limited control over their name and contents.
Patches
Fixed in @redocly/cli v2.33.2.
Workarounds
Do not run the split command on API descriptions from untrusted or unreviewed sources.
To detect an exploit attempt, inspect the description's component names andx-codeSamples lang values for a literal ../ — neither legitimately contains
path segments.
References
- WEB https://github.com/Redocly/redocly-cli/security/advisories/GHSA-657c-g7qc-r9j2
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-63225
- WEB https://github.com/Redocly/redocly-cli/pull/2891
- WEB https://github.com/Redocly/redocly-cli/pull/2923
- WEB https://github.com/Redocly/redocly-cli/commit/26a0f299fae0b3bb7bd513043d2f1e90e69f79ee
- WEB https://github.com/Redocly/redocly-cli/commit/504120419a72b5c684471478337ee3b45d8bfad3
- PACKAGE https://github.com/Redocly/redocly-cli
- WEB https://github.com/Redocly/redocly-cli/releases/tag/@redocly/cli@1.34.17
- WEB https://github.com/Redocly/redocly-cli/releases/tag/@redocly/cli@2.33.2
Ready to move
Start Securing
Free, no credit card | First findings in minutes