{"id":"CVE-2026-105801","title":"openapi-python-client generates Python clients from OpenAPI documents","summary":"openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Py…","severity":"high","cvss":8.4,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H","cwe":["CWE-94","CWE-116","CWE-150"],"vendor":"openapi-python-client","product":"openapi-python-client","affected":["openapi-python-client < 0.29.1"],"patched":["openapi-python-client 0.29.1"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T16:08:43.180","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105801","references":[{"url":"https://github.com/openapi-generators/openapi-python-client/commit/1c99af478892e5bbe6583b92acba431c9dec9186","label":"security-advisories@github.com"},{"url":"https://github.com/openapi-generators/openapi-python-client/pull/1483","label":"security-advisories@github.com"},{"url":"https://github.com/openapi-generators/openapi-python-client/releases/tag/v0.29.1","label":"security-advisories@github.com"},{"url":"https://github.com/openapi-generators/openapi-python-client/security/advisories/GHSA-5293-mq8x-g3xj","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105801"},{"url":"https://github.com/advisories/GHSA-5293-mq8x-g3xj"}],"tags":["nvd","ghsa","pip","cve.org"],"aliases":["GHSA-5293-mq8x-g3xj"],"ecosystem":"pip","cvssSource":"cna","ingestedAt":"2026-10-06T15:01:49.292Z","slug":"CVE-2026-105801","body":"## Overview\n\nopenapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that executes when a user imports the client, affecting the importing environment's integrity and potentially its confidentiality and availability. This issue is fixed in version 0.29.1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-105801)\n\nAffected packages:\n\n- `openapi-python-client < 0.29.1`\n\nPatched in:\n\n- `openapi-python-client 0.29.1`\n\nSource: https://github.com/advisories/GHSA-5293-mq8x-g3xj","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":46.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}