Vulnerability GHSA-7wgr-7666-7pwj
Low Risk
LOW RISK
CVSS Score: 3.0
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
6 years ago
August 20, 2020 at 02:38 PM UTC
Path Traversal in openapi-python-client
0.1.0.dev0 - 0.5.2
0.1.0.dev0 - 0.5.2
Summary
Path Traversal in openapi-python-client
Details
Impact
Path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.
Giving this a CVSS score of 3.0 (Low) with CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N/E:P/RL:U/RC:C
Patches
A fix is being worked on for version 0.5.3
Workarounds
Inspect OpenAPI documents before generating clients for them.
For more information
If you have any questions or comments about this advisory:
- Open an issue in openapi-python-client
- Email us at [email protected]
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 hours ago
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
0.1.0.dev0 - 0.29.0 GHSA-5293-mq8x-g3xj
0.1.0.dev0 - 0.29.0 GHSA-5293-mq8x-g3xj
High Risk
6 years ago
openapi-python-client Arbitrary Code Generation vulnerability
0.1.0.dev0 - 0.5.2 GHSA-9x4c-63pf-525f
0.1.0.dev0 - 0.5.2 GHSA-9x4c-63pf-525f
Unknown
6 years ago
No summary available
0.1.0.dev0 - 0.5.2 PYSEC-2020-70
0.1.0.dev0 - 0.5.2 PYSEC-2020-70
Unknown
6 years ago
No summary available
0.1.0.dev0 - 0.5.2 PYSEC-2020-71
0.1.0.dev0 - 0.5.2 PYSEC-2020-71
Impacted packages
Timeline
Published
6 years ago
August 20, 2020 at 02:38 PM UTC
Fixed (0.5.3)
6 years ago
August 13, 2020 at 05:23 PM UTC
Last Modified
26 days ago
September 10, 2026 at 03:48 AM UTC