Directory Traversal Vulnerability in DataModel Code Generator by Datamodel-Code-Generator
CVE-2026-107377
What is CVE-2026-107377?
The DataModel Code Generator is susceptible to a directory traversal vulnerability due to the handling of attacker-controlled Protobuf schemas. This allows the injection of absolute or parent-directory paths via the WEAK_IMPORT_PATTERN, potentially letting attackers manipulate file paths and create arbitrary directory trees or overwrite existing files during Protobuf compilation. This issue requires an automated job or a victim to process the adversarial schema within the context of grpcio-tools. While the exploitation may not achieve direct arbitrary code execution, it poses a significant risk by facilitating unintended file management operations. This vulnerability has been addressed in version 0.81.0.
Affected Version(s)
datamodel-code-generator >= 0.59.0, < 0.81.0
