CVE-2026-105801: openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
### Impact A malicious OpenAPI document processed by any `openapi-python-client` prior to 0.29.1 can generate arbitrary Python code. When anyone imports the malicious client, that arbitrary Python code will execute. ### Patches Versions starting with 0.29.1 have updated with guardrails to prevent arbitrary code generation. Upgrade to this version immediately and audit any code previously generated from untrusted documents. ### Workarounds Do not generate clients for documents you don't completely trust. Carefully verify any existing generated code from untrusted documents.
Recommended action
Recommended action
Upgrade affected packages to a patched version: openapi-python-client 0.29.1.
Technical details
- Vendor
- Not specified
- Product
- openapi-python-client
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source