Vulnerability DatabaseCVE-2026-105801

CVE-2026-105801: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-105801 is a code injection vulnerability in openapi-python-client, a tool that generates Python API clients from OpenAPI documents. Prior to version 0.29.1, the generator fails to safely neutralize malicious content embedded in OpenAPI documents before rendering it into string literals, docstrings, and f-strings in the generated Python code. This allows an attacker who controls an OpenAPI document to embed arbitrary Python code that executes automatically when a developer imports the generated client. The vulnerability affects all versions of openapi-python-client before 0.29.1 and was published on August 30, 2026, with CVE assignment on October 6, 2026. It carries a CVSS v4 base score of 8.4 (High) (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is improper output encoding and escaping (CWE-116, CWE-150) combined with improper control of code generation (CWE-94). When openapi-python-client processes an OpenAPI document, it renders user-controlled string values — such as field names, descriptions, enum values, and other metadata — directly into Python source code templates without sanitizing escape sequences or special characters. An attacker can craft an OpenAPI document containing payloads that break out of string literals, docstrings, or f-strings in the generated .py files, injecting arbitrary Python statements. The fix, implemented in PR #1483, involved a comprehensive rewrite of all string handling, introducing context-aware escaping functions (safe_for_docstring, in_f_string_literal, in_double_quote_literal) and stripping most Unicode control characters from string literals (GitHub PR #1483, GitHub Security Advisory).

Impact

Successful exploitation results in arbitrary Python code execution with the privileges of the user who imports the generated client module. The primary integrity impact is on the importing environment, where attacker-controlled code can modify system state, exfiltrate secrets, install backdoors, or pivot to other systems accessible from the developer's machine. Subsequent system impacts include high confidentiality, integrity, and availability risk, as the injected code runs in the developer's local environment — potentially affecting CI/CD pipelines, build systems, or any downstream consumers of the generated client (Github Advisory, GitHub Security Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Github Advisory). The EPSS score is 0.0, reflecting a very low probability of near-term exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires passive user interaction — a developer must generate a client from a malicious OpenAPI document and then import it — but requires no privileges and has low attack complexity once the attacker can supply the document.

Exploitation steps

  1. Craft a malicious OpenAPI document: Create an OpenAPI specification (JSON or YAML) that embeds Python code injection payloads within fields that get rendered into generated code, such as schema descriptions, property names, enum values, or operation summaries. For example, a description field containing """ import os; os.system('malicious_command') """ could break out of a docstring context.
  2. Deliver the document to the target: Distribute the malicious OpenAPI document via a public API registry, a shared repository, a supply-chain compromise, a phishing link, or by hosting it at a URL that a developer is likely to use with openapi-python-client generate --url.
  3. Trigger client generation: The victim developer runs openapi-python-client generate against the malicious document, causing the tool to render the injected payload into the generated Python source files without sanitization.
  4. Achieve code execution: When the developer (or an automated system such as a CI/CD pipeline) imports any module from the generated client package, the injected Python code executes immediately with the privileges of the importing process, enabling data exfiltration, persistence, or lateral movement (Github Advisory, GitHub PR #1483).

Indicators of compromise

  • File System: Generated Python client files (.py) containing unexpected executable statements outside of normal function/class definitions; presence of import os, import subprocess, exec(), eval(), or network-related imports in generated client modules; generated files containing string literal breaks (e.g., unmatched triple-quotes """) or f-string injection patterns.
  • Process: Unexpected child processes spawned by a Python interpreter during import of a generated client (e.g., shell commands, curl, wget, python -c).
  • Logs: CI/CD pipeline logs showing unexpected network connections or file writes during the import phase of generated client testing; Python tracebacks or unexpected output during module import in build logs.
  • Network: Outbound connections to unknown external hosts initiated by a Python process at import time, particularly from developer workstations or build servers running openapi-python-client.

Mitigation and workarounds

Upgrade openapi-python-client to version 0.29.1 or later immediately, as this release includes a comprehensive rewrite of string handling to prevent injection across all rendering contexts (GitHub Release v0.29.1). After upgrading, audit and regenerate any client code previously produced from untrusted or external OpenAPI documents, as previously generated files may still contain malicious code. As a workaround if upgrading is not immediately possible, only generate clients from OpenAPI documents whose full content you control and trust, and manually review all generated .py files before importing them (Github Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-105801HIGH8.4
  • Python logoPython
  • openapi-python-client
NoYesOct 06, 2026
GHSA-4v7v-gqf9-ww2gMEDIUM6.9
  • Python logoPython
  • vyper
NoYesOct 06, 2026
GHSA-2r3x-4mrv-mcxfMEDIUM6.9
  • Python logoPython
  • vyper
NoYesOct 06, 2026
GHSA-vg88-3v92-rjx2MEDIUM6.3
  • Python logoPython
  • vyper
NoYesOct 06, 2026
GHSA-j8f7-x8jm-wmm4MEDIUM6.3
  • Python logoPython
  • langflow-base
NoYesOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management