PatchSiren

Redocly CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Redocly CVE published 2026-09-16

CVE-2026-63325

The Redocly CLI vulnerability allows code execution via crafted OpenAPI descriptions. This issue arises from the dynamic evaluation of $faker runtime expressions in Arazzo descriptions, which can traverse constructor, prototype, or __proto__ properties and execute arbitrary code. Users processing only trusted, self-authored workflows are not affected. The vulnerability is fixed in @redocly/respect-core an [truncated]