CVE-2026-55390
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
28/07/2026
Last modified:
30/07/2026
Description
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside the input base path, allowing arbitrary local files to be read and reflected into generated models. This issue is fixed in version 0.62.0.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/koxudaxi/datamodel-code-generator/commit/d2d5cecd9fd3a2a6dbf148bf0740b83a11fc6820
- https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.62.0
- https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-442q-2j6p-642g
- https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-442q-2j6p-642g



