Remote Code Execution Risk in Datamodel-Code-Generator by Koxudaxi
CVE-2026-54690
8.2HIGH
What is CVE-2026-54690?
Datamodel-Code-Generator versions 0.9.1 to 0.61.0 are susceptible to a vulnerability where attacker-controlled JSON Schema $ref URLs can be silently dereferenced, potentially leading to server-side request forgery. This occurs during the processing of JSON Schema in the parser module. While the --allow-remote-refs option can warn users, it does not prevent the issue. Users are advised to update to version 0.61.0 or later to mitigate this risk.
Affected Version(s)
datamodel-code-generator >= 0.9.1, < 0.61.0
