openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that executes when a user imports the client, affecting the importing environment's integrity and potentially its confidentiality and availability. This issue is fixed in version 0.29.1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5293-mq8x-g3xj | openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that executes when a user imports the client, affecting the importing environment's integrity and potentially its confidentiality and availability. This issue is fixed in version 0.29.1. | |
| Title | openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation | |
| Weaknesses | CWE-116 CWE-150 CWE-94 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-06T14:53:42.461Z
Reserved: 2026-10-05T20:37:19.364Z
Link: CVE-2026-105801
No data.
Status : Deferred
Published: 2026-10-06T15:17:17.320
Modified: 2026-10-06T16:08:43.180
Link: CVE-2026-105801
No data.
OpenCVE Enrichment
Updated: 2026-10-06T18:30:05Z
Github GHSA