CVE-2026-105801: openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation
A malicious OpenAPI document processed by any openapi-python-client prior to 0.29.1 can generate arbitrary Python code. When anyone imports the malicious client, that arbitrary Python code will execute.
References
- github.com/advisories/GHSA-5293-mq8x-g3xj
- github.com/openapi-generators/openapi-python-client/commit/1c99af478892e5bbe6583b92acba431c9dec9186
- github.com/openapi-generators/openapi-python-client/pull/1483
- github.com/openapi-generators/openapi-python-client/releases/tag/v0.29.1
- github.com/openapi-generators/openapi-python-client/security/advisories/GHSA-5293-mq8x-g3xj
- nvd.nist.gov/vuln/detail/CVE-2026-105801
Code Behaviors & Features
Detect and mitigate CVE-2026-105801 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →