openapi-python-client
PyPI2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting openapi-python-clientpage 1 of 1
- CVE-2020-15141LOWCVSS 3.0EG 3.0✓ Fixed in 0.5.32020-08-14
vulnerable: 0.1.0.dev0 ... 0.5.2 (14 versions)
In openapi-python-client before version 0.5.3, there is a path traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on di…
- CVE-2020-15142HIGHCVSS 8.0EG 8.0✓ Fixed in 0.5.32020-08-14
vulnerable: 0.1.0.dev0 ... 0.5.2 (14 versions)
In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.
Check whether openapi-python-client is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for openapi-python-client CVEs against the assets you own.
Start Free Scan →