Code Injection Vulnerability in datamodel-code-generator from Koxudaxi
CVE-2026-54621

7.8HIGH

Key Information:

Vendor

Koxudaxi

Vendor
CVE Published:
28 July 2026

What is CVE-2026-54621?

The datamodel-code-generator tool, which translates schema definitions into Python data models, has a vulnerability that allows attacker-controlled GraphQL schema content to be leveraged for injecting Python code. Prior to version 0.60.1, issues in the rendering process meant that GraphQL Union description values were turned into Python comments without properly handling carriage returns, enabling code execution upon import of the generated models. This security flaw has been addressed in version 0.60.1, urging all users to upgrade.

Affected Version(s)

datamodel-code-generator >= 0.25.0, < 0.60.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.