THREAT OPS › Threat News › [GHSA] GHSA-657c-g7qc-r9j2 (medium) — Redocly CLI: Path traversal when using `split` command
[GHSA] GHSA-657c-g7qc-r9j2 (medium) — Redocly CLI: Path traversal when using `split` command
GHSA-657c-g7qc-r9j2 Severity: medium CVE: CVE-2026-63225
Redocly CLI: Path traversal when using `split` command
### Impact
An OpenAPI or AsyncAPI description could make the `split` command write files outside the chosen output directory, on the machine of anyone who runs `split` against it. The write is constrained rather than a free file-write primitive: component data is emitted only as YAML/
Indicators of compromise
- CVE-2026-63225cve
Original source: https://github.com/advisories/GHSA-657c-g7qc-r9j2