Koudai Aono datamodel-code-generator是日本Koudai Aono个人开发者的一款数据模型代码生成器。 Koudai Aono datamodel-code-generator 0.63.0之前版本存在安全漏洞,该漏洞源于在获取远程schema时跟随跨源重定向,重用Authorization、Cookie和Proxy-Authorization头,导致凭证泄露到另一个重定向目标。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| koxudaxi | datamodel-code-generator | < 0.63.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| koxudaxi | datamodel-code-generator | < 0.63.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54653 | 8.8 HIGH | `datamodel-code-generator` vulnerable to code injection in via attacker-controlled `defaul |
| CVE-2026-54691 | 8.2 HIGH | datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redi |
| CVE-2026-54690 | 8.2 HIGH | datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by |
| CVE-2026-54654 | 7.8 HIGH | `datamodel-code-generator` vulnerable to code injection via unescaped carriage return in ` |
| CVE-2026-54621 | 7.8 HIGH | `datamodel-code-generator` vulnerable to code injection via unescaped carriage return in G |
| CVE-2026-54655 | 7.8 HIGH | `datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON |
| CVE-2026-54656 | 7.8 HIGH | `datamodel-code-generator` vulnerable to code execution on import via unescaped `validator |
| CVE-2026-55390 | 7.5 HIGH | Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path travers |
| CVE-2026-55391 | 7.5 HIGH | datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding |
| CVE-2026-55389 | 7.5 HIGH | datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (` |
| CVE-2026-55415 | 7.5 HIGH | datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypeP |
No comments yet