Vulnerability GHSA-9x4c-63pf-525f

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
6 years ago
August 20, 2020 at 02:38 PM UTC
openapi-python-client Arbitrary Code Generation vulnerability
0.1.0.dev0 - 0.5.2
0.1.0.dev0 - 0.5.2

Summary

openapi-python-client Arbitrary Code Generation vulnerability

Details

Impact

Clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.

Giving this a CVSS of 8.0 (high) with CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H/E:P/RL:U/RC:C .

Patches

Fix will be included in version 0.5.3

Workarounds

Inspect OpenAPI documents before generating, or inspect generated code before executing.

For more information

If you have any questions or comments about this advisory:

Impacted packages

Timeline

Published
6 years ago
August 20, 2020 at 02:38 PM UTC
Fixed (0.5.3)
6 years ago
August 13, 2020 at 05:23 PM UTC
Last Modified
3 months ago
July 08, 2026 at 06:00 AM UTC