redocly-cli vulnerabilities
CVEs whose affected-version data names the redocly-cli package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-63325High· 7.8Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/respect-core and @redocly/cli, the respect command dynamically evaluates $faker runtime expressions in Arazzo descript…
▾ TwilightRedocly · redocly-cliEPSS 0.22%via NVD
CVE-2026-63225Medium· 4.4Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier
Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to @redocly/cli 2.33.2, the split command constructs output paths under --outDir from untrusted OpenAPI or AsyncAPI component names and x-codeSample…
▾ SunlitRedocly · redocly-cliEPSS 0.18%via NVD