Vulnerability Intelligence Report
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
CVE-2026-105801
openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that executes when a user imports the client, affecting the importing environment's integrity and potentially its confidentiality and availability. This issue is fixed in version 0.29.1.
No Active Exploit Signals
CVSS Base Score
8.4
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94: Improper Control of Generation of Code ('Code Injection')
CWE-116 ↗CWE-116: Improper Encoding or Escaping of Output
CWE-150 ↗CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| openapi-generators | openapi-python-client | < 0.29.1 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2026-10-05T20:37:19 |
| Published | 2026-10-06T14:53:42 |
| Last Updated | 2026-10-06T14:53:42 |
Community Chatter & Buzz