GHSA-5293-mq8x-g3xj: Code Injection

Published Oct 6, 2026
·
Updated

Impact A malicious OpenAPI document processed by any openapi-python-client prior to 0.29.1 can generate arbitrary Python code. When anyone imports the malicious client, that arbitrary Python code will execute.

Patches Versions starting with 0.29.1 have updated with guardrails to prevent arbitrary code generation. Upgrade to this version immediately and audit any code previously generated from untrusted documents.

Workarounds Do not generate clients for documents you don't completely trust. Carefully verify any existing generated code from untrusted documents.

Affected Software

1 affected componentFixes available
pip/openapi-python-client<0.29.1
0.29.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/openapi-python-client to a version that resolves this vulnerability.

    Fixed in 0.29.1
  2. Upgrade

    Upgrade openapi-python-client to a version that resolves this vulnerability.

    Fixed in 0.29.1
  3. Compensating control

    Do not generate clients for OpenAPI documents that are not completely trusted.

  4. Operational

    Carefully verify and audit any existing Python code generated from untrusted OpenAPI documents before use.

Event History

Oct 6, 2026
Advisory Published
via GitHub·03:32 PM
Data Sourced
via GitHub·03:32 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Who is exposed to this issue?

Anyone using openapi-python-client prior to 0.29.1 to generate a client from a malicious or otherwise untrusted OpenAPI document is exposed. The generated code becomes dangerous when someone imports that client.

2

What does an attacker need to exploit it?

An attacker needs to cause a malicious OpenAPI document to be processed by a vulnerable version of openapi-python-client. They also need the resulting generated client to be imported for the arbitrary generated Python code to execute.

3

What should be done if upgrading is not immediately possible?

Do not generate clients from any OpenAPI documents that are not completely trusted. Carefully review existing generated code that originated from untrusted documents before importing or using it.

4

How can teams determine whether they may already be affected?

Identify clients generated with openapi-python-client versions before 0.29.1 and determine whether their source OpenAPI documents were untrusted. Audit those generated clients for malicious Python code, especially before they are imported.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203