PT-2026-106762 · Pypi · Openapi-Python-Client

CVE-2026-105801

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions openapi-python-client versions prior to 0.29.1
Description The generator fails to safely neutralize malicious content from OpenAPI documents before rendering string, docstring, and f-string contexts in the generated Python code. This allows an attacker to inject arbitrary Python code into the generated client, which then executes when a user imports the client, compromising the integrity, confidentiality, and availability of the importing environment.
Recommendations Update to version 0.29.1 or later. Audit any code previously generated from untrusted documents. Avoid generating clients for documents from untrusted sources.

Exploit

Fix

Improper Encoding or Escaping of Output

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105801
GHSA-5293-MQ8X-G3XJ

Affected Products

Openapi-Python-Client