Arbitrary Code Execution Vulnerability in DataModel Code Generator by Koxudaxi
CVE-2026-54655

7.8HIGH

Key Information:

Vendor

Koxudaxi

Vendor
CVE Published:
28 July 2026

What is CVE-2026-54655?

The DataModel Code Generator by Koxudaxi, which automates the generation of Python data models from schema definitions, has a vulnerability in the handling of x-python-type values within JSON Schema. Versions between 0.51.0 and 0.60.2 fail to properly validate these values, allowing an attacker to manipulate the JSON Schema content. When the generated module is imported, this can result in the execution of arbitrary Python code, potentially compromising the security of applications that utilize the affected version.

Affected Version(s)

datamodel-code-generator >= 0.51.0, < 0.60.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.