CVE-2026-54653General(koxudaxi / datamodel-code-generator)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory values in src/datamodel_code_generator/parser/jsonschema.py through JsonSchemaObject.init and get_field_extras and emits them into Field(default_factory=...) or field(default_factory=...), allowing Python expression execution when the generated model is imported. This issue is fixed in version 0.60.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1336

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • datamodel-code-generator

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-07-29)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
datamodel-code-generator

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-23: 1Mentions · 2026-07-29: 206-2307-29
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-06-231
General1
2026-07-292
Disclosure1General1
Full discourse3 posts
  • Hamza@TheGr1ffyn
    General

    CVE-2026-54621 CVE-2026-54653 CVE-2026-54654 CVE-2026-54655 CVE-2026-54656 CVE-2026-54690 CVE-2026-54691 CVE-2026-55415 CVE-2026-55389 CVE-2026-55390 CVE-2026-55391 CVE-2026-55403

    Post summary

    The text lists multiple CVE identifiers without any accompanying details, leaving the nature and status of each vulnerability unknown.

    1000061
    132 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-54653 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YA… https://www.cve.org/CVERecord?id=CVE-2026-54653 ----- Traducción: CVE-2026-54653 dat… http://infoflow.cloud`

    Post summary

    The text offers a brief mention of CVE-2026-54653 linked to a tool and a reference to the CVE record, without providing technical details, exploit information, or mitigation steps.

    0000029
    96 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-54653 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YA… https://www.cve.org/CVERecord?id=CVE-2026-54653

    Post summary

    The post announces CVE‑2026‑54653 for datamodel‑code‑generator without providing technical details, patch information, or exploitation evidence.

    00000696
    57.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkoxudaxidatamodel-code-generator---

Explore more