CVE-2026-54690General(koxudaxi / datamodel-code-generator)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch koxudaxi datamodel-code-generator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.9.1 until 0.61.0, datamodel-code-generator silently dereferences attacker-controlled JSON Schema $ref HTTP or HTTPS URLs in src/datamodel_code_generator/parser/jsonschema.py through _get_ref_body, and the --allow-remote-refs gate can warn instead of blocking, allowing server-side request forgery through src/datamodel_code_generator/http.py. This issue is fixed in version 0.61.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • datamodel-code-generator

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-29); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
datamodel-code-generator

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-06-23: 1Mentions · 2026-07-29: 2Mentions · 2026-07-30: 1Mentions · 2026-08-01: 1Patch / Workaround · 2026-08-01: 1Technical Details · 2026-07-30: 1Technical Details · 2026-08-01: 106-2307-2907-3008-01
Signal classification2 categories
General
360.0%
Disclosure
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-231
General1
2026-07-292
General2
2026-07-301
Disclosure1
2026-08-011
Disclosure1
Full discourse5 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-54690 - SSRF in datamodel-code-generator. CVSS 8.2. Attacker-controlled JSON Schema refs can trigger server-side request forgery. No patch available. Mitigate by restricting remote refs. #CVE #infosec #cybersecurity #cvealert #redteam #blueteam #syadmin #devsecops #devops #python #linux #developer #developers https://www.valtersit.com/cve/CVE-2026-54690/

    Post summary

    The post announces an SSRF vulnerability (CVE-2026-54690) in datamodel-code-generator with CVSS 8.2, notes the lack of a patch, and suggests mitigation by restricting remote JSON Schema refs.

    0001051
    978 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-54690 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YA… https://www.cve.org/CVERecord?id=CVE-2026-54690

    Post summary

    The post merely references CVE‑2026‑54690 and notes a code generator’s functionality, with no indication of exploitation, patches, or detailed technical information.

    00010845
    57.9K followersView on X
  • Hamza@TheGr1ffyn
    General

    CVE-2026-54621 CVE-2026-54653 CVE-2026-54654 CVE-2026-54655 CVE-2026-54656 CVE-2026-54690 CVE-2026-54691 CVE-2026-55415 CVE-2026-55389 CVE-2026-55390 CVE-2026-55391 CVE-2026-55403

    Post summary

    A list of CVE identifiers is provided without any additional context or details.

    1000061
    132 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-54690: SSRF Vulnerability in datamodel-code-generator Exposes Internal Resources. https://ift.tt/0XfweqV

    Post summary

    The tweet announces CVE‑2026‑54690, an SSRF flaw in datamodel‑code‑generator that can expose internal resources, and links to a source for further details.

    0000049
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-54690 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YA… https://www.cve.org/CVERecord?id=CVE-2026-54690 ----- Traducción: CVE-2026-54690 dat… http://infoflow.cloud`

    Post summary

    The tweet merely references CVE‑2026‑54690 and links to its CVE record, without providing any detailed vulnerability, exploitation, or mitigation information.

    0000027
    96 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkoxudaxidatamodel-code-generator---

Explore more