datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside the input base path, allowing arbitrary local files to be read and reflected into generated models. This issue is fixed in version 0.62.0.
References
Configurations
No configuration.
History
29 Jul 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/koxudaxi/datamodel-code-generator/security/advisories/GHSA-442q-2j6p-642g - |
28 Jul 2026, 22:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-28 22:17
Updated : 2026-07-30 20:02
NVD link : CVE-2026-55390
Mitre link : CVE-2026-55390
CVE.ORG link : CVE-2026-55390
JSON object : View
Products Affected
No product.
