CVE-2020-15141 describes a path traversal vulnerability in openapi-python-client versions prior to 0.5.3. This flaw allows an attacker to craft a malicious OpenAPI document that, when used to generate a client, can place arbitrary files in unintended locations on the disk. The vulnerability has a CVSS score of 4.1 (MEDIUM), indicating a low complexity attack requiring user interaction (UI:R) and low privileges (PR:L) over a network (AV:N). While it does not impact confidentiality or availability, it can lead to unauthorized file modification (I:L). There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.3CPE matchmatch criteria | cpe:2.3:a:openapi-python-client_project:openapi-python-client:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.