Skip to content
Threat Feed
high advisory

Arbitrary Code Generation in openapi-python-client

The openapi-python-client library is vulnerable to arbitrary code generation when processing malicious OpenAPI documents, leading to remote code execution upon importing the generated client.

CVE search metadata

CVE search record: CVE-2026-105801. KEV: no. Product: openapi-python-client (< 0.29.1). Brief: Arbitrary Code Generation in openapi-python-client. Brief link: https://feed.craftedsignal.io/briefs/2026-10-openapi-python-client-rce/

The openapi-python-client library (versions prior to 0.29.1) contains a vulnerability identified as CVE-2026-105801. An attacker can craft a malicious OpenAPI document that, when processed by the library, results in the injection and generation of arbitrary Python code within the output. This vulnerability poses a significant risk to the software supply chain, as developers unknowingly import and execute this generated code within their own environments. The impact is direct arbitrary code execution upon the import of the generated client module. Defenders and developers should prioritize updating the library to version 0.29.1 or later. Furthermore, organizations should conduct a retroactive audit of all client code generated from untrusted or third-party OpenAPI documents to identify potential backdoors or malicious modifications.

Impact

Successful exploitation allows for arbitrary code execution in the context of the user or system running the generated Python client. This affects any application utilizing openapi-python-client for automation of API client generation, particularly those integrating untrusted external schemas. If malicious code is generated and embedded in a production codebase, it could lead to full system compromise or data exfiltration.

Recommendation

  • Upgrade the openapi-python-client dependency to version 0.29.1 or higher immediately across all development and build environments.
  • Audit existing projects for client code generated via openapi-python-client prior to the patch, specifically searching for unauthorized file system access, network connections, or unexpected subprocess invocations.
  • Implement a policy to only process OpenAPI documents from verified, trusted sources for automated client generation.

Immediate actions

Upgrade openapi-python-client to 0.29.1 or later

Development Teams 24h

Mitigations

Audit codebases for generated clients from untrusted OpenAPI documents

immediate Security Operations

CVE-2026-105801