In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-15142.json"