Remote Code Execution Risk in Datamodel-Code-Generator by Koxudaxi
CVE-2026-54690

8.2HIGH

Key Information:

Vendor

Koxudaxi

Vendor
CVE Published:
28 July 2026

What is CVE-2026-54690?

Datamodel-Code-Generator versions 0.9.1 to 0.61.0 are susceptible to a vulnerability where attacker-controlled JSON Schema $ref URLs can be silently dereferenced, potentially leading to server-side request forgery. This occurs during the processing of JSON Schema in the parser module. While the --allow-remote-refs option can warn users, it does not prevent the issue. Users are advised to update to version 0.61.0 or later to mitigate this risk.

Affected Version(s)

datamodel-code-generator >= 0.9.1, < 0.61.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.