CVE-2026-63225 Overview
CVE-2026-63225 is a path traversal vulnerability [CWE-22] in Redocly CLI, a tool that streamlines OpenAPI validation, linting, and documentation workflows. Versions prior to @redocly/cli 2.33.2 fail to validate output paths in the split command. The command constructs file paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSamples lang values without confirming the resolved target stays inside the selected directory.
An attacker can craft a specification containing literal ../ traversal segments in these fields. Processing the file with split causes the CLI to place or overwrite files outside the intended --outDir.
Critical Impact
Local users processing untrusted OpenAPI or AsyncAPI documents with the split command may have files written or overwritten outside the designated output directory.
Affected Products
- @redocly/cli versions prior to 2.33.2 (2.x branch)
- @redocly/cli versions prior to 1.34.17 (1.x branch)
- Redocly CLI split command consumers processing untrusted OpenAPI or AsyncAPI documents
Discovery Timeline
- 2026-09-16 - CVE CVE-2026-63225 published to NVD
- 2026-09-16 - Last updated in NVD database
Technical Details for CVE-2026-63225
Vulnerability Analysis
The Redocly CLI split command decomposes a single OpenAPI or AsyncAPI document into a directory tree of component files. It derives output filenames from component names inside the input document and from the lang field of x-codeSamples entries. Prior to version 2.33.2, the code joined these attacker-influenced strings directly with the --outDir base path without a containment check.
When a component name contains ../ sequences, the resolved path escapes the intended output directory. The split command then writes or overwrites files at that arbitrary location using the current process privileges. The written content is constrained to YAML or JSON serializations of component data, and code-sample filenames remain tied to the HTTP method, so this is not arbitrary-content file write.
Root Cause
The root cause is missing path canonicalization and containment validation in the split output pipeline. Functions in packages/cli/src/commands/split/ constructed destinations using path.join(componentDirPath, componentName) without verifying that the resolved absolute path remained within --outDir. Any traversal segment supplied through component identifiers or x-codeSampleslang values propagated directly to filesystem writes.
Attack Vector
Exploitation requires a local user to invoke redocly split against a malicious OpenAPI or AsyncAPI document. User interaction is required, and the attacker cannot trigger the write remotely without convincing an operator to process the file. Once processed, files are written outside --outDir, which can overwrite adjacent project files, CI artifacts, or configuration siblings depending on where split was executed.
// Security patch adding the containment check
// Source: https://github.com/Redocly/redocly-cli/commit/504120419a72b5c684471478337ee3b45d8bfad3
function assertWithinDir(baseDir: string, targetPath: string, subject: string) {
const base = path.resolve(baseDir);
const target = path.resolve(targetPath);
if (target !== base && !target.startsWith(base + path.sep)) {
exitWithError(`Refusing to write "${subject}" outside the output directory.`);
}
}
The fix resolves both the base and target paths, then requires the target to equal the base or begin with the base followed by a path separator. Companion changes in iterate-asyncapi-channels.ts and iterate-asyncapi-components.ts import and invoke assertWithinDir before every write. See Redocly CLI Pull Request #2891 and Redocly CLI Pull Request #2923.
Detection Methods for CVE-2026-63225
Indicators of Compromise
- Files appearing outside the --outDir path after running redocly split, particularly with .yaml, .yml, or .json extensions
- OpenAPI or AsyncAPI documents containing component names or x-codeSampleslang fields with ../ sequences or absolute path prefixes
- Unexpected modification timestamps on project files sibling to the intended split output directory
Detection Strategies
- Scan OpenAPI and AsyncAPI documents in repositories and pipelines for component keys and x-codeSamples.lang values matching regex patterns containing .., /, or \
- Audit CI/CD logs for redocly split invocations preceding unexpected file changes outside the declared output directory
- Enumerate installed @redocly/cli versions across developer workstations and build agents; flag any version below 1.34.17 or 2.33.2
Monitoring Recommendations
- Enable filesystem auditing on directories that host build tooling and API specification repositories to capture writes outside expected output roots
- Alert on process executions of redocly or npx @redocly/cli in CI runners that write to paths outside the working directory
- Track dependency manifests (package.json, package-lock.json) for downgrades of @redocly/cli to vulnerable versions
How to Mitigate CVE-2026-63225
Immediate Actions Required
- Upgrade @redocly/cli to version 2.33.2 or later on the 2.x branch, or 1.34.17 or later on the 1.x branch
- Refuse to run redocly split against OpenAPI or AsyncAPI documents received from untrusted sources until upgrades complete
- Review recent split outputs on shared build systems for files written outside intended directories and restore any overwritten content from source control
Patch Information
The vulnerability is fixed in @redocly/cli 2.33.2 and backported to 1.34.17. The fix introduces an assertWithinDir helper that resolves the target path and rejects any write that escapes --outDir. Review the Redocly Security Advisory GHSA-657c-g7qc-r9j2, the Redocly CLI Release v2.33.2, and the Redocly CLI Release v1.34.17 for full details.
Workarounds
- Execute redocly split only against OpenAPI or AsyncAPI documents authored or reviewed by trusted maintainers
- Run redocly split inside an isolated container or sandbox with a dedicated writable directory and no access to sensitive host paths
- Pre-process input specifications to strip or reject component names and x-codeSamples.lang values containing ../, ..\\, or absolute path prefixes
# Upgrade to the patched release
npm install --save-dev @redocly/cli@^2.33.2
# Or, for the 1.x branch
npm install --save-dev @redocly/cli@^1.34.17
# Verify the installed version
npx @redocly/cli --version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
