<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T19:54:15.951555+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-342351</id>
    <title>EUVD-2026-342351</title>
    <updated>2026-10-05T19:54:15.955781+00:00</updated>
    <content>EUVD-2026-342351</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-342351"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55415</id>
    <title>fkie_cve-2026-55415</title>
    <updated>2026-10-05T19:54:15.955814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.11.6 until 0.64.0, datamodel-code-generator allows attacker-controlled x-python-import or customTypePath schema extensions to reach src/datamodel_code_generator/parser/jsonschema.py and generated import handling through Import.from_full_path and Imports.create_line in src/datamodel_code_generator/imports.py, allowing a newline to break out of an import statement and execute Python code when the generated model is imported. This issue is fixed in version 0.64.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-55415"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5578-w22f-pfx9</id>
    <title>GHSA-5578-w22f-pfx9 — datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import stat…</title>
    <updated>2026-10-05T19:54:15.955847+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: datamodel-code-generator</p>
<p>#### Summary</p>
<p>A malicious input schema (OpenAPI / JSON Schema) can execute arbitrary Python code on the machine that **imports** the generated model. The `x-python-import` and `customTypePath` schema extensions flow, unsanitized, into the `import` statements datamodel-code-generator emits. A newline embedded in the extension value breaks out of the `from … import …` line and injects an attacker-controlled statement at module scope, which runs at import time. This is an unauthenticated, schema-content–driven remote code execution against any consumer of the generated code (e.g. arbitrary file read,the PoC exfiltrates `/etc/passwd`). It survives the v0.61.0 security release that fixed the related `x-python-type`, `default_factory`, GraphQL-union-description, and `validators` sinks  those fixes did not cover this sibling path.</p>
<p>#### Details</p>
<p>The sink is `Import.from_full_path` and `Imports.create_line`:</p>
<p>- `src/datamodel_code_generator/imports.py:35` — `from_full_path()` only does `class_path.split(".")` and preserves every other character, **including newlines**:
  ```python
  @classmethod
  @lru_cache
  def from_full_path(cls, class_path: str) -&gt; Import:
      split_class_path: list[str] = class_path.split(".")
      return cls(import_=split_class_path[-1], from_=".".join(split_class_path[:-1]) or None)
  ```
- `src/datamodel_code_generator/imports.py:64` — `create_line()` renders the result verbatim:
  ```python
  def create_line(self, from_: str | None, imports: set[str]) -…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5578-w22f-pfx9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3557</id>
    <title>PYSEC-2026-3557 — datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import stat…</title>
    <updated>2026-10-05T19:54:15.955920+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: datamodel-code-generator</p>
<p>#### Summary</p>
<p>A malicious input schema (OpenAPI / JSON Schema) can execute arbitrary Python code on the machine that **imports** the generated model. The `x-python-import` and `customTypePath` schema extensions flow, unsanitized, into the `import` statements datamodel-code-generator emits. A newline embedded in the extension value breaks out of the `from … import …` line and injects an attacker-controlled statement at module scope, which runs at import time. This is an unauthenticated, schema-content–driven remote code execution against any consumer of the generated code (e.g. arbitrary file read,the PoC exfiltrates `/etc/passwd`). It survives the v0.61.0 security release that fixed the related `x-python-type`, `default_factory`, GraphQL-union-description, and `validators` sinks  those fixes did not cover this sibling path.</p>
<p>#### Details</p>
<p>The sink is `Import.from_full_path` and `Imports.create_line`:</p>
<p>- `src/datamodel_code_generator/imports.py:35` — `from_full_path()` only does `class_path.split(".")` and preserves every other character, **including newlines**:
  ```python
  @classmethod
  @lru_cache
  def from_full_path(cls, class_path: str) -&gt; Import:
      split_class_path: list[str] = class_path.split(".")
      return cls(import_=split_class_path[-1], from_=".".join(split_class_path[:-1]) or None)
  ```
- `src/datamodel_code_generator/imports.py:64` — `create_line()` renders the result verbatim:
  ```python
  def create_line(self, from_: str | None, imports: set[str]) -…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3557"/>
  </entry>
</feed>
