CVE-2026-105801
8.4
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
Summary
openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that executes when a user imports the client, affecting the importing environment's integrity and potentially its confidentiality and availability. This issue is fixed in version 0.29.1.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| openapi-generators | openapi-python-client | < 0.29.1 | affected |
Weaknesses
- CWE-94: CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-116: CWE-116: Improper Encoding or Escaping of Output
- CWE-150: CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences
References
- https://github.com/openapi-generators/openapi-python-client/security/advisories/GHSA-5293-mq8x-g3xj
- https://github.com/openapi-generators/openapi-python-client/pull/1483
- https://github.com/openapi-generators/openapi-python-client/commit/1c99af478892e5bbe6583b92acba431c9dec9186
- https://github.com/openapi-generators/openapi-python-client/releases/tag/v0.29.1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.