Vulnerability GHSA-9x4c-63pf-525f
High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
6 years ago
August 20, 2020 at 02:38 PM UTC
openapi-python-client Arbitrary Code Generation vulnerability
0.1.0.dev0 - 0.5.2
0.1.0.dev0 - 0.5.2
Summary
openapi-python-client Arbitrary Code Generation vulnerability
Details
Impact
Clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.
Giving this a CVSS of 8.0 (high) with CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H/E:P/RL:U/RC:C .
Patches
Fix will be included in version 0.5.3
Workarounds
Inspect OpenAPI documents before generating, or inspect generated code before executing.
For more information
If you have any questions or comments about this advisory:
- Open an issue in openapi-python-client
- Email us at [email protected]
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 hours ago
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
0.1.0.dev0 - 0.29.0 GHSA-5293-mq8x-g3xj
0.1.0.dev0 - 0.29.0 GHSA-5293-mq8x-g3xj
Low Risk
6 years ago
Path Traversal in openapi-python-client
0.1.0.dev0 - 0.5.2 GHSA-7wgr-7666-7pwj
0.1.0.dev0 - 0.5.2 GHSA-7wgr-7666-7pwj
Unknown
6 years ago
No summary available
0.1.0.dev0 - 0.5.2 PYSEC-2020-70
0.1.0.dev0 - 0.5.2 PYSEC-2020-70
Unknown
6 years ago
No summary available
0.1.0.dev0 - 0.5.2 PYSEC-2020-71
0.1.0.dev0 - 0.5.2 PYSEC-2020-71
Impacted packages
Timeline
Published
6 years ago
August 20, 2020 at 02:38 PM UTC
Fixed (0.5.3)
6 years ago
August 13, 2020 at 05:23 PM UTC
Last Modified
3 months ago
July 08, 2026 at 06:00 AM UTC