CVE-2026-55389General(koxudaxi / datamodel-code-generator)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch koxudaxi datamodel-code-generator systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_generator/parser/jsonschema.py through is_url and _get_ref_body without containing file:// or ../ traversal references to the input directory and without honoring --no-allow-remote-refs, allowing arbitrary local file reads. This issue is fixed in version 0.62.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-200CWE-610

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • datamodel-code-generator

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-07-29); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
datamodel-code-generator

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-06-23: 1Mentions · 2026-07-29: 3Mentions · 2026-08-01: 1Patch / Workaround · 2026-08-01: 1Technical Details · 2026-07-29: 1Technical Details · 2026-08-01: 106-2307-2908-01
Signal classification3 categories
General
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-231
General1
2026-07-293
Disclosure2General1
2026-08-011
Patch1
Full discourse5 posts
  • HOL@HashgraphOnline
    Disclosure

    datamodel-code-generator (pip) lets a JSON-Schema `$ref` with `file://` or `../` traversal read any file the process can, bypassing --no-allow-remote-refs. Agents running codegen on untrusted schemas hand attackers filesystem read. CVE-2026-55389 https://github.com/advisories/GHSA-8359-h9fx-j6v9

    Post summary

    The post announces that datamodel-code-generator mishandles JSON‑Schema $refs, permitting arbitrary file reads, without providing PoC code, exploit details, or patch information.

    10060810
    19.1K followersView on X
  • Hamza@TheGr1ffyn
    General

    CVE-2026-54621 CVE-2026-54653 CVE-2026-54654 CVE-2026-54655 CVE-2026-54656 CVE-2026-54690 CVE-2026-54691 CVE-2026-55415 CVE-2026-55389 CVE-2026-55390 CVE-2026-55391 CVE-2026-55403

    Post summary

    The post simply lists a series of CVE identifiers with no contextual or technical details.

    1000061
    132 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2026-55389 (CVSS 7.5) datamodel-code-generator vulnerable to arbitrary local file reads via path traversal in JSON Schema ﹩ref handling. Affected: versions < 0.62.0 ✅ Fixed in v0.62.0 Patch immediately. #CVE #Vulnerability #PatchNow https://t.co/WARmA3jMqH

    Post summary

    The tweet alerts users to CVE-2026-55389, a high‑severity path traversal flaw in datamodel-code-generator that permits local file reads, and recommends updating to version 0.62.0 as the fix.

    0000053
    99 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-55389 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YA… https://www.cve.org/CVERecord?id=CVE-2026-55389 ----- Traducción: CVE-2026-55389 dat… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑55389 for datamodel‑code‑generator, but offers no detailed technical, exploit, or mitigation information.

    0000027
    96 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-55389 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YA… https://www.cve.org/CVERecord?id=CVE-2026-55389

    Post summary

    The text links to the CVE record for CVE-2026-55389, providing no information on exploitation, patching, or technical details.

    00000729
    57.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkoxudaxidatamodel-code-generator---

Explore more