OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-105801: openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation

GitHub Advisories · officialPublished Oct 6, 2026Risk 37/100

### Impact A malicious OpenAPI document processed by any `openapi-python-client` prior to 0.29.1 can generate arbitrary Python code. When anyone imports the malicious client, that arbitrary Python code will execute. ### Patches Versions starting with 0.29.1 have updated with guardrails to prevent arbitrary code generation. Upgrade to this version immediately and audit any code previously generated from untrusted documents. ### Workarounds Do not generate clients for documents you don't completely trust. Carefully verify any existing generated code from untrusted documents.

Upgrade affected packages to a patched version: openapi-python-client 0.29.1.

Vendor
Not specified
Product
openapi-python-client
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source