


Perceptive Security
SOC/SIEM Consultancy

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_code_generator…
Published:
27 July 2026 at 22:00:00
Alert date:
28 July 2026 at 23:04:30
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
A code injection vulnerability exists in datamodel-code-generator prior to version 0.60.1. The flaw resides in Jinja2 templates used to generate Python models from GraphQL Union type definitions. GraphQL Union description values are rendered into Python comments without neutralizing carriage return characters, allowing attacker-controlled GraphQL schema content to inject arbitrary Python code into generated model files. This injected code executes automatically when the generated Python modules are imported. The vulnerability affects two template files: UnionTypeStatement.jinja2 and UnionTypeStatement.py312.jinja2. Exploitation requires an attacker to control or influence the GraphQL schema input provided to the code generator. The issue has been remediated in version 0.60.1 of datamodel-code-generator.
Technical details
Mitigation steps:
Affected products:
datamodel-code-generator
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54621
https://github.com/koxudaxi/datamodel-code-generator/commit/aec47bc414779f4a9992b3919c8f7663afd6c988
https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.60.1
https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-j884-q54q-mmx3
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
