openapi-python-client is vulnerable to Code Injection
84
High Risk
The code generator embeds values taken from the input OpenAPI document directly into generated Python literals, docstrings, f-strings, identifiers, and expressions without escaping them. A malicious or untrusted OpenAPI specification can break out of these contexts and inject arbitrary Python code into the generated client. The injected code runs when a developer imports or uses the generated client, resulting in arbitrary code execution. The fix treats OpenAPI-derived values as untrusted, applies context-specific escaping, and rejects unsafe template rendering.
You are affected if you are using a version that falls within the vulnerable range and you generate clients from untrusted or externally controlled OpenAPI documents.
openapi-python-client is vulnerable to Code Injection in versions 0.0.1 - 0.29.0.
Upgrade the openapi-python-client library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.