PT-2026-106762 · Pypi · Openapi-Python-Client
CVE-2026-105801
·
Published
2026-10-06
·
Updated
2026-10-06
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
openapi-python-client versions prior to 0.29.1
Description
The generator fails to safely neutralize malicious content from OpenAPI documents before rendering string, docstring, and f-string contexts in the generated Python code. This allows an attacker to inject arbitrary Python code into the generated client, which then executes when a user imports the client, compromising the integrity, confidentiality, and availability of the importing environment.
Recommendations
Update to version 0.29.1 or later.
Audit any code previously generated from untrusted documents.
Avoid generating clients for documents from untrusted sources.
Exploit
Fix
Improper Encoding or Escaping of Output
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openapi-Python-Client