Path traversal when using `preview-docs` when working dir contains files with question mark `?` in nameGHSA-q324-q795-2q5p
Fix: Redocly/openapi-cli#347GHSA-q324-q795-2q5p is a security vulnerability in @redocly/openapi-cli. A fix is available for @redocly/openapi-cli — see the affected versions and patch details below.
Real-World Exposure
How broadly this vulnerability is actually deployed: weekly install volume shows current usage, a proxy for how much of the ecosystem is exposed.
@redocly/openapi-clinpmDescription
Impact
preview-docs command allows path traversal if current working dir contains files with question mark ? in name and attacker knows the name.
Patches
It was patched starting from 1.0.0-beta.59
Workarounds
Do not run openapi-cli preview-docs command in the folder which contains files with question mark ? in name.
References
https://github.com/Redocly/openapi-cli/pull/347
For more information
If you have any questions or comments about this advisory:
- Open an issue in @redocly/openapi-cli
- Email us at [email protected]
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | @redocly/openapi-cli | all versions | 1.0.0-beta.59npm install @redocly/openapi-cli@1.0.0-beta.59 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for @redocly/openapi-cli, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update @redocly/openapi-cli to 1.0.0-beta.59 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-q324-q795-2q5p is resolved across your whole dependency graph.
Workarounds
Resolve every user-supplied path to its canonical form and reject anything that escapes the intended directory, and run the component under an account that has no read or write access outside the directory it legitimately serves.
Frequently Asked Questions
Is GHSA-q324-q795-2q5p in your dependencies?
Find it across npm, including transitive dependencies.