Remote Code Execution Vulnerability in Datamodel Code Generator from Koxudaxi
CVE-2026-54653

8.8HIGH

Key Information:

Vendor

Koxudaxi

Vendor
CVE Published:
28 July 2026

What is CVE-2026-54653?

The Datamodel Code Generator by Koxudaxi allows remote code execution due to inadequate handling of default_factory values in versions 0.17.0 through 0.60.2. This vulnerability can be exploited as the attacker-controlled values are preserved and executed in Python expressions when importing the generated models. Users are urged to upgrade to version 0.60.2 or later to mitigate this risk and ensure the security of their applications.

Affected Version(s)

datamodel-code-generator >= 0.17.0, < 0.60.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.