


Perceptive Security
SOC/SIEM Consultancy

datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel_code_gener…
Published:
28 juli 2026 om 00:00:00
Alert date:
29 juli 2026 om 01:04:30
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies, Security Tools
A code injection vulnerability exists in datamodel-code-generator versions 0.51.0 through 0.60.1. The library, which generates Python data models from schema definitions, fails to sufficiently validate x-python-type values parsed from JSON Schema files. Attacker-controlled JSON Schema content can insert malicious Python code into generated field annotations. This code executes when the generated module is imported, enabling arbitrary code execution. The vulnerable function is _get_python_type_override in src/datamodel_code_generator/parser/jsonschema.py. The vulnerability is classified as a supply chain risk since it affects code generation tooling. The issue was fixed in version 0.60.2. Developers using this tool to process untrusted schema files are at risk.
Technical details
Mitigation steps:
Affected products:
datamodel-code-generator 0.51.0 - 0.60.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54655
https://github.com/koxudaxi/datamodel-code-generator/commit/2c93c9b712f43391dcfa975a1e4aa0b7c93ccbba
https://github.com/koxudaxi/datamodel-code-generator/releases/tag/0.60.2
https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-m34r-v34r-rf9q
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
