PT-2026-93911 · Npm · @Redocly/Respect-Core+1
CVE-2026-63325
·
Published
2026-09-16
·
Updated
2026-09-16
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
@redocly/respect-core versions prior to 2.33.0
@redocly/cli versions prior to 2.33.0
Description
The
respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or proto properties within the get-value-from-context.ts file to reach the JavaScript Function constructor. This allows the execution of arbitrary code with the privileges of the CLI process, potentially enabling the execution of shell commands or the reading of CI secrets, when a user processes an untrusted description.Recommendations
Update @redocly/respect-core to version 2.33.0.
Update @redocly/cli to version 2.33.0.
Exploit
Fix
Eval Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Redocly-Cli
@Redocly/Respect-Core