Security: koxudaxi/datamodel-code-generator
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Code Injection via schema-controlled `customBasePath`GHSA-8qcx-gvfr-p397 published
Aug 14, 2026 by koxudaxiHigh -
Authorization / request headers leaked to cross-origin redirect target when fetching remote schemasGHSA-r5vv-ff45-prp2 published
Jun 12, 2026 by koxudaxiLow -
SSRF protection bypass via DNS rebindingGHSA-vx7x-vcc2-c44g published
Jun 12, 2026 by koxudaxiHigh -
Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gateGHSA-442q-2j6p-642g published
Jun 12, 2026 by koxudaxiHigh -
Arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`GHSA-8359-h9fx-j6v9 published
Jun 12, 2026 by koxudaxiHigh -
Code injection via `x-python-import` / `customTypePath` in generated import statementsGHSA-5578-w22f-pfx9 published
Jun 12, 2026 by koxudaxiHigh -
SSRF in datamodel-code-generator via JSON-Schema `$ref` to HTTP URL (silent by default)GHSA-954p-556p-r752 published
Jun 8, 2026 by koxudaxiHigh -
SSRF in datamodel-code-generator via --url: no host/IP validation, follows redirectsGHSA-rfr2-mq9m-x2qx published
Jun 8, 2026 by koxudaxiHigh -
Code execution on import via unescaped `validators` entries in --extra-template-dataGHSA-8m8r-38jm-f355 published
Jun 8, 2026 by koxudaxiHigh -
Code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generatorGHSA-m34r-v34r-rf9q published
Jun 8, 2026 by koxudaxiHigh