
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-105801 is a code injection vulnerability in openapi-python-client, a tool that generates Python API clients from OpenAPI documents. Prior to version 0.29.1, the generator fails to safely neutralize malicious content embedded in OpenAPI documents before rendering it into string literals, docstrings, and f-strings in the generated Python code. This allows an attacker who controls an OpenAPI document to embed arbitrary Python code that executes automatically when a developer imports the generated client. The vulnerability affects all versions of openapi-python-client before 0.29.1 and was published on August 30, 2026, with CVE assignment on October 6, 2026. It carries a CVSS v4 base score of 8.4 (High) (Github Advisory, GitHub Security Advisory).
The root cause is improper output encoding and escaping (CWE-116, CWE-150) combined with improper control of code generation (CWE-94). When openapi-python-client processes an OpenAPI document, it renders user-controlled string values — such as field names, descriptions, enum values, and other metadata — directly into Python source code templates without sanitizing escape sequences or special characters. An attacker can craft an OpenAPI document containing payloads that break out of string literals, docstrings, or f-strings in the generated .py files, injecting arbitrary Python statements. The fix, implemented in PR #1483, involved a comprehensive rewrite of all string handling, introducing context-aware escaping functions (safe_for_docstring, in_f_string_literal, in_double_quote_literal) and stripping most Unicode control characters from string literals (GitHub PR #1483, GitHub Security Advisory).
Successful exploitation results in arbitrary Python code execution with the privileges of the user who imports the generated client module. The primary integrity impact is on the importing environment, where attacker-controlled code can modify system state, exfiltrate secrets, install backdoors, or pivot to other systems accessible from the developer's machine. Subsequent system impacts include high confidentiality, integrity, and availability risk, as the injected code runs in the developer's local environment — potentially affecting CI/CD pipelines, build systems, or any downstream consumers of the generated client (Github Advisory, GitHub Security Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is 0.0, reflecting a very low probability of near-term exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires passive user interaction — a developer must generate a client from a malicious OpenAPI document and then import it — but requires no privileges and has low attack complexity once the attacker can supply the document.
""" import os; os.system('malicious_command') """ could break out of a docstring context.openapi-python-client generate --url.openapi-python-client generate against the malicious document, causing the tool to render the injected payload into the generated Python source files without sanitization..py) containing unexpected executable statements outside of normal function/class definitions; presence of import os, import subprocess, exec(), eval(), or network-related imports in generated client modules; generated files containing string literal breaks (e.g., unmatched triple-quotes """) or f-string injection patterns.import of a generated client (e.g., shell commands, curl, wget, python -c).import phase of generated client testing; Python tracebacks or unexpected output during module import in build logs.openapi-python-client.Upgrade openapi-python-client to version 0.29.1 or later immediately, as this release includes a comprehensive rewrite of string handling to prevent injection across all rendering contexts (GitHub Release v0.29.1). After upgrading, audit and regenerate any client code previously produced from untrusted or external OpenAPI documents, as previously generated files may still contain malicious code. As a workaround if upgrading is not immediately possible, only generate clients from OpenAPI documents whose full content you control and trust, and manually review all generated .py files before importing them (Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."