Skip to main content
Vulnerability Database/CVE-2026-63325

CVE-2026-63325: Redocly CLI RCE Vulnerability

CVE-2026-63325 is a remote code execution flaw in Redocly CLI that allows attackers to execute arbitrary code through crafted $faker expressions. This post explains its technical details, affected versions, and mitigation steps.

Published:

CVE-2026-63325 Overview

CVE-2026-63325 is a code injection vulnerability [CWE-94] in Redocly CLI and the @redocly/respect-core package. The respect command dynamically evaluates $faker runtime expressions embedded in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or __proto__ properties in packages/respect-core/src/modules/context-parser/get-value-from-context.ts to reach the JavaScript Function constructor and execute arbitrary code. The flaw affects any user who processes an untrusted Arazzo description. Redocly fixed the issue in version 2.33.0 of @redocly/respect-core and @redocly/cli.

Critical Impact

Attackers who supply a malicious Arazzo description can execute arbitrary code with the privileges of the CLI process, including shell commands and access to CI/CD secrets.

Affected Products

  • @redocly/cli prior to version 2.33.0
  • @redocly/respect-core prior to version 2.33.0
  • @redocly/respect-core 1.x prior to version 1.34.17

Discovery Timeline

  • 2026-09-16 - CVE-2026-63325 published to NVD
  • 2026-09-16 - Last updated in NVD database

Technical Details for CVE-2026-63325

Vulnerability Analysis

Redocly CLI provides validation, linting, and documentation tooling for OpenAPI and Arazzo workflows. The respect command executes Arazzo workflow descriptions and resolves runtime expressions such as $faker.* to generate test data. The resolver in get-value-from-context.ts walks object properties using attacker-controlled path segments without filtering dangerous keys.

By traversing constructor, prototype, or __proto__, an expression can pivot from a benign faker object to the JavaScript Function constructor. Invoking Function with attacker-supplied source produces a callable that executes arbitrary JavaScript in the Node.js process. The executed code inherits the environment of the CLI invocation, which in continuous integration commonly includes deployment tokens, cloud credentials, and repository write access.

Root Cause

The resolver treats property lookups on the runtime context as data access rather than a security boundary. It does not maintain an allowlist of faker functions or reject reserved property names. Any string in the runtime expression path becomes a property lookup, enabling prototype traversal to reach language-level primitives that support dynamic code evaluation.

Attack Vector

Exploitation requires a user to run redocly respect against an Arazzo description authored by an attacker. Delivery vectors include pull requests to shared repositories, third-party API definitions consumed during CI, and documentation packages fetched from untrusted sources. Users who process only trusted, self-authored workflows are not affected. Successful exploitation yields code execution as the CLI user and can lead to shell command execution and exfiltration of CI secrets. See the GitHub Security Advisory GHSA-xw2f-5386-m542 for the vendor description.

Detection Methods for CVE-2026-63325

Indicators of Compromise

  • Arazzo description files containing $faker expressions with tokens such as constructor, prototype, or __proto__ in the property path.
  • Unexpected child processes (sh, bash, curl, wget, node -e) spawned by redocly or node during CI runs of the respect command.
  • Outbound network connections from CI runners to unknown hosts during Arazzo processing.
  • Access to environment variables containing secrets (GITHUB_TOKEN, AWS_*, NPM_TOKEN) immediately after invoking redocly respect.

Detection Strategies

  • Scan repositories and pipeline inputs for Arazzo YAML/JSON containing runtime expressions that reference constructor, prototype, __proto__, or Function.
  • Instrument CI runners to log the full process tree spawned from redocly invocations and alert on shell descendants.
  • Compare the installed version of @redocly/cli and @redocly/respect-core against 2.33.0 across build agents and developer workstations.

Monitoring Recommendations

  • Forward CI runner process, file, and network telemetry to a centralized analytics platform for correlation across builds.
  • Alert on secret access patterns that occur within the execution window of documentation or API linting jobs.
  • Track npm dependency drift so that vulnerable versions of @redocly/cli reintroduced through transitive dependencies trigger a review.

How to Mitigate CVE-2026-63325

Immediate Actions Required

  • Upgrade @redocly/cli and @redocly/respect-core to version 2.33.0 or later. Users on the 1.x line of @redocly/respect-core should install 1.34.17.
  • Audit CI pipelines that execute redocly respect against externally sourced Arazzo descriptions and rotate any secrets that were exposed to those jobs.
  • Restrict CI job permissions and secret scopes so that documentation tooling runs with the minimum credentials required.

Patch Information

The fix is included in @redocly/respect-core 2.33.0 and back-ported to @redocly/respect-core 1.34.17. The patch is implemented in commit d26d452 and delivered through Pull Request #2881 and Pull Request #2922.

Workarounds

  • Do not run redocly respect against Arazzo descriptions from untrusted authors, including third-party pull requests, until upgrades complete.
  • Execute the CLI inside an ephemeral sandbox or container that has no access to production secrets or long-lived credentials.
  • Pre-scan Arazzo descriptions for the strings constructor, prototype, __proto__, and Function and reject files that contain them in runtime expressions.
bash
# Upgrade the CLI and respect-core to patched versions
npm install --save-dev @redocly/cli@^2.33.0 @redocly/respect-core@^2.33.0

# Verify the installed versions
npm ls @redocly/cli @redocly/respect-core

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.