Vulnerability GHSA-5293-mq8x-g3xj

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 06, 2026 at 03:32 PM UTC
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
0.1.0.dev0 - 0.29.0
0.1.0.dev0 - 0.29.0

Summary

openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation

Details

Impact

A malicious OpenAPI document processed by any openapi-python-client prior to 0.29.1 can generate arbitrary Python code. When anyone imports the malicious client, that arbitrary Python code will execute.

Patches

Versions starting with 0.29.1 have updated with guardrails to prevent arbitrary code generation. Upgrade to this version immediately and audit any code previously generated from untrusted documents.

Workarounds

Do not generate clients for documents you don't completely trust. Carefully verify any existing generated code from untrusted documents.

Impacted packages

Timeline

Published
2 hours ago
October 06, 2026 at 03:32 PM UTC
Fixed (0.29.1)
1 month ago
August 30, 2026 at 07:39 PM UTC
Last Modified
2 hours ago
October 06, 2026 at 03:46 PM UTC