{"id":"CVE-2024-35219","summary":"OpenAPI Generator Online - Arbitrary File Read/Delete","details":"OpenAPI Generator allows generation of API client libraries (SDK generation), server stubs, documentation and configuration automatically given an OpenAPI Spec. Prior to version 7.6.0, attackers can exploit a path traversal vulnerability to read and delete files and folders from an arbitrary, writable directory as anyone can set the output folder when submitting the request via the `outputFolder` option. The issue was fixed in version 7.6.0 by removing the usage of the `outputFolder` option. No known workarounds are available.","aliases":["GHSA-g3hr-p86p-593h"],"modified":"2026-08-12T15:15:16.196363Z","published":"2024-05-27T16:11:22.875Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35219.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/35xxx/CVE-2024-35219.json"},{"type":"ADVISORY","url":"https://github.com/OpenAPITools/openapi-generator/security/advisories/GHSA-g3hr-p86p-593h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-35219"},{"type":"FIX","url":"https://github.com/OpenAPITools/openapi-generator/commit/edbb021aadae47dcfe690313ce5119faf77f800d"},{"type":"FIX","url":"https://github.com/OpenAPITools/openapi-generator/pull/18652"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openapitools/openapi-generator","events":[{"introduced":"0"},{"fixed":"edbb021aadae47dcfe690313ce5119faf77f800d"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"7.6.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v7.5.0","v7.4.0","v7.3.0","v7.2.0","v7.1.0","v7.0.1","v7.0.0","v7.0.0-beta","v6.6.0","v6.5.0","v6.4.0","v6.3.0","v6.2.0","v6.1.0","v6.0.1","v6.0.0","v6.0.0-beta","v5.4.0","v5.3.1","v5.3.0","v5.2.1","v5.2.0","v5.1.1","v5.1.0","v5.0.0","v5.0.0-beta3","v5.0.0-beta2","v5.0.0-beta","v4.3.1","v4.3.0","v4.2.3","v4.2.2","v4.2.1","v4.2.0","v4.1.0","v4.0.3","v4.0.2","v4.0.1","v4.0.0","v4.0.0-beta3","v4.0.0-beta2","v3.0.1","v3.0.0","v2.3.1","v2.3.0","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.1.6","v2.1.5","v2.1.4","v2.1.3","v2.1.2","v2.1.0-M2","v2.1.2-M1","v2.1.1-M1","v2.1.0-M1","v2.0.18","2.0.17","swagger-codegen_2.9.1-2.0.1","swagger-codegen_2.9.1-2.0.0","swagger-codegen_2.9.1-1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-35219.json","vanir_signatures_modified":"2026-08-12T15:15:16Z","vanir_signatures":[{"target":{"function":"generate","file":"modules/openapi-generator-online/src/main/java/org/openapitools/codegen/online/service/Generator.java"},"deprecated":false,"digest":{"function_hash":"292791088695023562045633448309077987949","length":3030},"id":"CVE-2024-35219-5cdcbac8","signature_type":"Function","signature_version":"v1","source":"https://github.com/openapitools/openapi-generator/commit/edbb021aadae47dcfe690313ce5119faf77f800d"},{"deprecated":false,"digest":{"line_hashes":["43190614658561776477550092621110787076","80927479154937598328395991210732610671","123691282334315019541914364421378614959","240165886498530612982760901500924825998","66866291717537235861393697126915984796","25070708890358108909974422701122393665","133820808557899456395946771386966864487","140989231131170536759822518733779762046","237843721166161890867131407379618978134","305428317451008999249602305551583561942"],"threshold":0.9},"id":"CVE-2024-35219-b3b304a0","signature_type":"Line","signature_version":"v1","source":"https://github.com/openapitools/openapi-generator/commit/edbb021aadae47dcfe690313ce5119faf77f800d","target":{"file":"modules/openapi-generator-online/src/main/java/org/openapitools/codegen/online/service/Generator.java"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H"}]}