Remote Code Execution Risk in Python Client Generator by OpenAPI Generators
CVE-2026-105801

8.4HIGH

Key Information:

Vendor
CVE Published:
6 October 2026

What is CVE-2026-105801?

The OpenAPI Python client has a vulnerability that allows an attacker to craft malicious content in OpenAPI documents, which, when processed by the client generator, can lead to the generation of Python code containing attacker-controlled code. This code executes when the user imports the generated client, jeopardizing the integrity, confidentiality, and availability of the importing environment. Users are urged to upgrade to version 0.29.1 or later to mitigate this risk.

Affected Version(s)

openapi-python-client < 0.29.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.