<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Openapi-Python-Client (&lt; 0.29.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/openapi-python-client--0.29.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 18:48:36 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/openapi-python-client--0.29.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Code Generation in openapi-python-client</title><link>https://feed.craftedsignal.io/briefs/2026-10-openapi-python-client-rce/</link><pubDate>Tue, 06 Oct 2026 18:48:36 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-openapi-python-client-rce/</guid><description>The openapi-python-client library is vulnerable to arbitrary code generation when processing malicious OpenAPI documents, leading to remote code execution upon importing the generated client.</description><content:encoded><![CDATA[<p>The openapi-python-client library (versions prior to 0.29.1) contains a vulnerability identified as CVE-2026-105801. An attacker can craft a malicious OpenAPI document that, when processed by the library, results in the injection and generation of arbitrary Python code within the output. This vulnerability poses a significant risk to the software supply chain, as developers unknowingly import and execute this generated code within their own environments. The impact is direct arbitrary code execution upon the import of the generated client module. Defenders and developers should prioritize updating the library to version 0.29.1 or later. Furthermore, organizations should conduct a retroactive audit of all client code generated from untrusted or third-party OpenAPI documents to identify potential backdoors or malicious modifications.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution in the context of the user or system running the generated Python client. This affects any application utilizing openapi-python-client for automation of API client generation, particularly those integrating untrusted external schemas. If malicious code is generated and embedded in a production codebase, it could lead to full system compromise or data exfiltration.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the openapi-python-client dependency to version 0.29.1 or higher immediately across all development and build environments.</li>
<li>Audit existing projects for client code generated via openapi-python-client prior to the patch, specifically searching for unauthorized file system access, network connections, or unexpected subprocess invocations.</li>
<li>Implement a policy to only process OpenAPI documents from verified, trusted sources for automated client generation.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>code-execution</category><category>python</category></item></channel></rss>