<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:31:15.707822+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-55390</id>
    <title>CVE-2026-55390 — Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate</title>
    <updated>2026-10-04T09:31:15.709530+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> koxudaxi datamodel-code-generator</p>
<p>datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside the input base path, allowing arbitrary local files to be read and reflected into generated models. This issue is fixed in version 0.62.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-55390"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-442q-2j6p-642g</id>
    <title>GHSA-442q-2j6p-642g — datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) pa…</title>
    <updated>2026-10-04T09:31:15.709585+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: datamodel-code-generator</p>
<p>### Summary</p>
<p>When generating models from an XML Schema (`--input-file-type xmlschema`), `datamodel-code-generator` resolves `&lt;xs:include&gt;`, `&lt;xs:import&gt;`, `&lt;xs:redefine&gt;`, and `&lt;xs:override&gt;` `schemaLocation` attributes against the source directory and reads the target with no restriction to the input/base directory. An attacker who controls the input XSD can read arbitrary files via `../` traversal or an absolute path, and the included schema's contents (type names, restrictions, enumerations) are folded into the generated output. Unlike the JSON-Schema `$ref` path, there is no `allow_remote_refs` control for XSD, so `--no-allow-remote-refs` does not mitigate it. This is an unauthenticated path-traversal / information-disclosure issue reachable in the default configuration.</p>
<p>### Details</p>
<p>The XSD parser walks include-style children and reads each `schemaLocation` with only an `is_file()` check (`src/datamodel_code_generator/parser/xmlschema.py`):</p>
<p>```python
location = (source_dir / schema_location).resolve()   # .resolve() collapses ../, escapes base
if location in seen or not location.is_file():
    continue
included_root = self._parse_schema(_read_xml_text(location, self.encoding), location)
```</p>
<p>`schema_location` is attacker-controlled and `_read_xml_text` does `path.read_bytes()`. Because `(source_dir / schema_location).resolve()` normalizes `..` and accepts absolute paths, the resolved target can be any file the process can read; there is no `is_relative_to(base_path)`…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-442q-2j6p-642g"/>
  </entry>
</feed>
