{"id":"GHSA-q324-q795-2q5p","aliases":[],"url":"https://o3.security/vulnerability/GHSA-q324-q795-2q5p","summary":"Path traversal when using `preview-docs` when working dir contains files with question mark `?` in name","details":"### Impact\n`preview-docs` command allows path traversal if current working dir contains files with question mark `?` in name and attacker knows the name.\n\n### Patches\nIt was patched starting from 1.0.0-beta.59\n\n### Workarounds\nDo not run openapi-cli preview-docs command in the folder which contains files with question mark `?` in name.\n\n### References\nhttps://github.com/Redocly/openapi-cli/pull/347\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [@redocly/openapi-cli](https://github.com/Redocly/openapi-cli)\n* Email us at [security@redocly.com](mailto:security@redocly.com)\n","published":"2021-10-12T16:05:11Z","modified":"2021-10-11T18:40:44Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@redocly/openapi-cli","fixedVersion":"1.0.0-beta.59"}],"fix":{"url":"https://github.com/Redocly/openapi-cli/pull/347","label":"Redocly/openapi-cli#347"},"references":[{"type":"WEB","url":"https://github.com/Redocly/openapi-cli/security/advisories/GHSA-q324-q795-2q5p"},{"type":"WEB","url":"https://github.com/Redocly/openapi-cli/pull/347"},{"type":"PACKAGE","url":"https://github.com/Redocly/openapi-cli"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2021-10-11T18:40:44Z"}}