Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redocly
Redocly redoc |
|
| Vendors & Products |
Redocly
Redocly redoc |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__ properties in packages/respect-core/src/modules/context-parser/get-value-from-context.ts, reach the JavaScript Function constructor, and execute arbitrary code when a user processes an untrusted description. The executed code runs with the privileges of the CLI process and can execute shell commands or read CI secrets. Users processing only trusted, self-authored workflows are not affected. This issue is fixed in @redocly/respect-core and @redocly/cli version 2.33.0. | |
| Title | Redocly CLI: Arbitrary code execution via Arazzo `$faker` expression using `respect` | |
| Weaknesses | CWE-94 CWE-95 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-18T18:23:39.395Z
Reserved: 2026-07-16T14:14:24.384Z
Link: CVE-2026-63325
Updated: 2026-09-18T18:23:35.313Z
Status : Received
Published: 2026-09-16T19:17:24.317
Modified: 2026-09-18T19:16:44.693
Link: CVE-2026-63325
No data.
OpenCVE Enrichment
Updated: 2026-09-18T21:45:14Z