Local File Read Vulnerability in datamodel-code-generator Tool by koxudaxi
CVE-2026-55389
7.5HIGH
What is CVE-2026-55389?
The datamodel-code-generator tool, which generates Pydantic v2 models from various data formats, has a vulnerability that allows arbitrary local file reads. This occurs when resolving JSON Schema references without appropriate restrictions, making it possible for unauthorized users to access sensitive files on the system. This issue was addressed in version 0.62.0, which implemented necessary safeguards against such vulnerabilities.
Affected Version(s)
datamodel-code-generator < 0.62.0
