{"id":"GHSA-7wgr-7666-7pwj","summary":"Path Traversal in openapi-python-client","details":"### Impact\nPath traversal vulnerability. If a user generated a client using a maliciously crafted OpenAPI document, it is possible for generated files to be placed in arbitrary locations on disk.\n\nGiving this a CVSS score of 3.0 (Low) with CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N/E:P/RL:U/RC:C\n\n### Patches\nA fix is being worked on for version 0.5.3\n\n### Workarounds\nInspect OpenAPI documents before generating clients for them.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [openapi-python-client](https://github.com/triaxtec/openapi-python-client/issues)\n* Email us at [danthony@triaxtec.com](mailto:danthony@triaxtec.com)","aliases":["CVE-2020-15141","PYSEC-2020-70"],"modified":"2026-09-10T03:48:30.732585870Z","published":"2020-08-20T14:38:13Z","database_specific":{"github_reviewed_at":"2020-08-14T16:08:41Z","nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"LOW","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/triaxtec/openapi-python-client/security/advisories/GHSA-7wgr-7666-7pwj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-15141"},{"type":"WEB","url":"https://github.com/triaxtec/openapi-python-client/commit/3e7dfae5d0b3685abf1ede1bc6c086a116ac4746"},{"type":"PACKAGE","url":"https://github.com/openapi-generators/openapi-python-client"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/openapi-python-client/PYSEC-2020-70.yaml"},{"type":"WEB","url":"https://github.com/triaxtec/openapi-python-client/blob/main/CHANGELOG.md#053---2020-08-13"},{"type":"WEB","url":"https://pypi.org/project/openapi-python-client"}],"affected":[{"package":{"name":"openapi-python-client","ecosystem":"PyPI","purl":"pkg:pypi/openapi-python-client"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.3"}]}],"versions":["0.1.0","0.1.0.dev0","0.1.1","0.1.2","0.2.0","0.2.1","0.3.0","0.4.0","0.4.0rc1","0.4.1","0.4.2","0.5.0","0.5.1","0.5.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-7wgr-7666-7pwj/GHSA-7wgr-7666-7pwj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N"}]}