CVE-2026-105801 PUBLISHED

openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation

Assigner: GitHub_M
Reserved: 05.10.2026 Published: 06.10.2026 Updated: 06.10.2026

openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that executes when a user imports the client, affecting the importing environment's integrity and potentially its confidentiality and availability. This issue is fixed in version 0.29.1.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
CVSS Score: 8.4

Product Status

Vendor openapi-generators
Product openapi-python-client
Versions
  • Version < 0.29.1 is affected

References

Problem Types

  • CWE-94: Improper Control of Generation of Code ('Code Injection') CWE
  • CWE-116: Improper Encoding or Escaping of Output CWE
  • CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences CWE