{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openapi-python-client--0.29.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openapi-python-client_project:openapi-python-client:*:*:*:*:*:python:*:*"],"_cs_cves":[{"id":"CVE-2026-105801"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["openapi-python-client (\u003c 0.29.1)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","code-execution","python"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe openapi-python-client library (versions prior to 0.29.1) contains a vulnerability identified as CVE-2026-105801. An attacker can craft a malicious OpenAPI document that, when processed by the library, results in the injection and generation of arbitrary Python code within the output. This vulnerability poses a significant risk to the software supply chain, as developers unknowingly import and execute this generated code within their own environments. The impact is direct arbitrary code execution upon the import of the generated client module. Defenders and developers should prioritize updating the library to version 0.29.1 or later. Furthermore, organizations should conduct a retroactive audit of all client code generated from untrusted or third-party OpenAPI documents to identify potential backdoors or malicious modifications.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution in the context of the user or system running the generated Python client. This affects any application utilizing openapi-python-client for automation of API client generation, particularly those integrating untrusted external schemas. If malicious code is generated and embedded in a production codebase, it could lead to full system compromise or data exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the openapi-python-client dependency to version 0.29.1 or higher immediately across all development and build environments.\u003c/li\u003e\n\u003cli\u003eAudit existing projects for client code generated via openapi-python-client prior to the patch, specifically searching for unauthorized file system access, network connections, or unexpected subprocess invocations.\u003c/li\u003e\n\u003cli\u003eImplement a policy to only process OpenAPI documents from verified, trusted sources for automated client generation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T18:48:36Z","date_published":"2026-10-06T18:48:36Z","id":"https://feed.craftedsignal.io/briefs/2026-10-openapi-python-client-rce/","summary":"The openapi-python-client library is vulnerable to arbitrary code generation when processing malicious OpenAPI documents, leading to remote code execution upon importing the generated client.","title":"Arbitrary Code Generation in openapi-python-client","url":"https://feed.craftedsignal.io/briefs/2026-10-openapi-python-client-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Openapi-Python-Client (\u003c 0.29.1)","version":"https://jsonfeed.org/version/1.1"}