CVE-2026-55390

HIGH

datamodel-code-generator 0.59.0-0.62.0 - XSD Path Traversal File Read

Title source: manual
STIX 2.1

Description

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside the input base path, allowing arbitrary local files to be read and reflected into generated models. This issue is fixed in version 0.62.0.

Scores

CVSS v3 7.5
EPSS 0.0036
EPSS Percentile 28.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-200 CWE-22 CWE-610
Status published
Products (2)
koxudaxi/datamodel-code-generator >= 0.59.0, < 0.62.0
pypi/datamodel-code-generator 0.59.0 - 0.62.0PyPI
Published Jul 28, 2026
Tracked Since Jul 29, 2026