CVE-2026-105801High· 8.4▾ Twilightopenapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Py…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 46.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
openapi-python-client generates Python clients from OpenAPI documents. Prior to 0.29.1, the generator does not safely neutralize malicious OpenAPI document content before rendering string, docstring, and f-string contexts in generated Python. The generated Python client can contain attacker-controlled Python that executes when a user imports the client, affecting the importing environment's integrity and potentially its confidentiality and availability. This issue is fixed in version 0.29.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
openapi-python-client < 0.29.1Patched in:
openapi-python-client 0.29.1Connected by shared product, vendor, weakness, or advisory.
CVE-2020-15141Low· 3.0Path Traversal in openapi-python-client
CVE-2020-15142High· 8.0openapi-python-client Arbitrary Code Generation vulnerability
CVE-2026-25755High· 8.1jsPDF is a library to generate PDFs in JavaScript
GHSA-jqmf-mx4f-hfr6Critical· 10.0Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF
CVE-2026-90999Critical· 9.8Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment
CVE-2026-57583Low· 3.3OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelin Contracts