PT-2026-93911 · Npm · @Redocly/Respect-Core+1

CVE-2026-63325

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @redocly/respect-core versions prior to 2.33.0 @redocly/cli versions prior to 2.33.0
Description The respect command dynamically evaluates $faker runtime expressions in Arazzo descriptions. A crafted expression can traverse constructor, prototype, or proto properties within the get-value-from-context.ts file to reach the JavaScript Function constructor. This allows the execution of arbitrary code with the privileges of the CLI process, potentially enabling the execution of shell commands or the reading of CI secrets, when a user processes an untrusted description.
Recommendations Update @redocly/respect-core to version 2.33.0. Update @redocly/cli to version 2.33.0.

Exploit

Fix

Eval Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63325
GHSA-XW2F-5386-M542

Affected Products

Redocly-Cli
@Redocly/Respect-Core