Path traversal when using `preview-docs` when working dir contains files with question mark `?` in name
Package
Affected versions
<= 1.0.0-beta.58
Patched versions
1.0.0-beta.59
Description
Reviewed
Oct 11, 2021
Published to the GitHub Advisory Database
Oct 12, 2021
Last updated
Jan 9, 2023
Impact
preview-docs
command allows path traversal if current working dir contains files with question mark?
in name and attacker knows the name.Patches
It was patched starting from 1.0.0-beta.59
Workarounds
Do not run openapi-cli preview-docs command in the folder which contains files with question mark
?
in name.References
Redocly/redocly-cli#347
For more information
If you have any questions or comments about this advisory:
References