← Back to CVE List
Vulnerability Intelligence Report
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation

CVE-2026-105801

openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that executes when a user imports the client, affecting the importing environment's integrity and potentially its confidentiality and availability. This issue is fixed in version 0.29.1.

No Active Exploit Signals
CVSS Base Score
8.4
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-94 ↗CWE-94: Improper Control of Generation of Code ('Code Injection')
CWE-116 ↗CWE-116: Improper Encoding or Escaping of Output
CWE-150 ↗CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences

Affected Products & Versions

Vendor Product Affected Versions
openapi-generators openapi-python-client < 0.29.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-10-05T20:37:19
Published2026-10-06T14:53:42
Last Updated2026-10-06T14:53:42

LINK COPIED TO CLIPBOARD