THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-657c-g7qc-r9j2 (medium) — Redocly CLI: Path traversal when using `split` command

[GHSA] GHSA-657c-g7qc-r9j2 (medium) — Redocly CLI: Path traversal when using `split` command

medgithub_advisoriesPublished 2026-09-17

GHSA-657c-g7qc-r9j2 Severity: medium CVE: CVE-2026-63225

Redocly CLI: Path traversal when using `split` command

### Impact

An OpenAPI or AsyncAPI description could make the `split` command write files outside the chosen output directory, on the machine of anyone who runs `split` against it. The write is constrained rather than a free file-write primitive: component data is emitted only as YAML/

Indicators of compromise

Original source: https://github.com/advisories/GHSA-657c-g7qc-r9j2