GHSA-5293-mq8x-g3xj: Code Injection
Impact A malicious OpenAPI document processed by any openapi-python-client prior to 0.29.1 can generate arbitrary Python code. When anyone imports the malicious client, that arbitrary Python code will execute.
Patches Versions starting with 0.29.1 have updated with guardrails to prevent arbitrary code generation. Upgrade to this version immediately and audit any code previously generated from untrusted documents.
Workarounds Do not generate clients for documents you don't completely trust. Carefully verify any existing generated code from untrusted documents.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/openapi-python-clientto a version that resolves this vulnerability.Fixed in 0.29.1 - Upgrade
Upgrade
openapi-python-clientto a version that resolves this vulnerability.Fixed in 0.29.1 - Compensating control
Do not generate clients for OpenAPI documents that are not completely trusted.
- Operational
Carefully verify and audit any existing Python code generated from untrusted OpenAPI documents before use.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Anyone using openapi-python-client prior to 0.29.1 to generate a client from a malicious or otherwise untrusted OpenAPI document is exposed. The generated code becomes dangerous when someone imports that client.
What does an attacker need to exploit it?
An attacker needs to cause a malicious OpenAPI document to be processed by a vulnerable version of openapi-python-client. They also need the resulting generated client to be imported for the arbitrary generated Python code to execute.
What should be done if upgrading is not immediately possible?
Do not generate clients from any OpenAPI documents that are not completely trusted. Carefully review existing generated code that originated from untrusted documents before importing or using it.
How can teams determine whether they may already be affected?
Identify clients generated with openapi-python-client versions before 0.29.1 and determine whether their source OpenAPI documents were untrusted. Audit those generated clients for malicious Python code, especially before they are imported.