HIGH
Redocly
CVE published 2026-09-16
CVE-2026-63325
The Redocly CLI vulnerability allows code execution via crafted OpenAPI descriptions. This issue arises from the dynamic evaluation of $faker runtime expressions in Arazzo descriptions, which can traverse constructor, prototype, or __proto__ properties and execute arbitrary code. Users processing only trusted, self-authored workflows are not affected. The vulnerability is fixed in @redocly/respect-core an [truncated]