—
PYSEC-2020-71
Quick fix
PYSEC-2020-71 — openapi-python-client: upgrade to the fixed version with the command below.
pip install --upgrade 'openapi-python-client>=f7a56aae32cba823a77a84a1f10400799b19c19a'Details
In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/openapi-python-client
Introduced in:
0Fixed in: f7a56aae32cba823a77a84a1f10400799b19c19aFix
pip install --upgrade 'openapi-python-client>=f7a56aae32cba823a77a84a1f10400799b19c19a'References
- https://github.com/triaxtec/openapi-python-client/blob/main/CHANGELOG.md#053---2020-08-13[WEB]
- https://pypi.org/project/openapi-python-client/[PACKAGE]
- https://github.com/triaxtec/openapi-python-client/commit/f7a56aae32cba823a77a84a1f10400799b19c19a[FIX]
- https://github.com/triaxtec/openapi-python-client/security/advisories/GHSA-9x4c-63pf-525f[ADVISORY]