<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 10 Oct 2026 11:59:15 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-342322</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342322</link>
      <description>EUVD-2026-342322</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342322</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54653</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54653</link>
      <description>&lt;p&gt;datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From  0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory values in src/datamodel_code_generator/parser/jsonschema.py through JsonSchemaObject.init and get_field_extras and emits them into Field(default_factory=...) or field(default_factory=...), allowing Python expression execution when the generated model is imported. This issue is fixed in version 0.60.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From  0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory values in src/datamodel_code_generator/parser/jsonschema.py through JsonSchemaObject.init and get_field_extras and emits them into Field(default_factory=...) or field(default_factory=...), allowing Python expression execution when the generated model is imported. This issue is fixed in version 0.60.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54653</guid>
    </item>
    <item>
      <title>GHSA-386q-5hp3-95m9 — `datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-386q-5hp3-95m9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`datamodel-code-generator` is vulnerable to code injection when generating Python models from an attacker-controlled JSON Schema, OpenAPI, YAML, JSON, Avro, Protobuf, or XSD schema. When a property carries a `&amp;#34;default_factory&amp;#34;` key, its value is interpolated verbatim — as a raw Python expression — into the generated `Field(default_factory=...)` / `field(default_factory=...)` call. Because this assignment is evaluated at class-definition time (i.e. on `import` of the generated module), an attacker who controls the schema controls a Python expression that runs in the consumer&amp;#39;s process. No special CLI flags are required.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable chain spans the JSON-Schema-shaped parser and three sink locations (Pydantic v2, dataclass, msgspec):&lt;/p&gt;
&lt;p&gt;**Source — schema → `extras`**:&lt;/p&gt;
&lt;p&gt;- `src/datamodel_code_generator/parser/jsonschema.py:600-614` — `DEFAULT_FIELD_KEYS` includes the literal string `&amp;#34;default_factory&amp;#34;`.
- `src/datamodel_code_generator/parser/jsonschema.py:457-459` — `JsonSchemaObject.__init__` stores any non-standard key (including `default_factory`) in `self.extras`.
- `src/datamodel_code_generator/parser/jsonschema.py:797-812` — `get_field_extras` preserves `default_factory` through to the field model.&lt;/p&gt;
&lt;p&gt;**Sinks — `extras` → generated Python expression**:&lt;/p&gt;
&lt;p&gt;1. `src/datamodel_code_generator/model/pydantic_base.py:222-249`:&lt;/p&gt;
&lt;p&gt;```python
   default_factory = data.pop(&amp;#34;default_factory&amp;#34;, None)
   ...
   if default_factory is not None:
       field_arguments…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`datamodel-code-generator` is vulnerable to code injection when generating Python models from an attacker-controlled JSON Schema, OpenAPI, YAML, JSON, Avro, Protobuf, or XSD schema. When a property carries a `&amp;#34;default_factory&amp;#34;` key, its value is interpolated verbatim — as a raw Python expression — into the generated `Field(default_factory=...)` / `field(default_factory=...)` call. Because this assignment is evaluated at class-definition time (i.e. on `import` of the generated module), an attacker who controls the schema controls a Python expression that runs in the consumer&amp;#39;s process. No special CLI flags are required.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable chain spans the JSON-Schema-shaped parser and three sink locations (Pydantic v2, dataclass, msgspec):&lt;/p&gt;
&lt;p&gt;**Source — schema → `extras`**:&lt;/p&gt;
&lt;p&gt;- `src/datamodel_code_generator/parser/jsonschema.py:600-614` — `DEFAULT_FIELD_KEYS` includes the literal string `&amp;#34;default_factory&amp;#34;`.
- `src/datamodel_code_generator/parser/jsonschema.py:457-459` — `JsonSchemaObject.__init__` stores any non-standard key (including `default_factory`) in `self.extras`.
- `src/datamodel_code_generator/parser/jsonschema.py:797-812` — `get_field_extras` preserves `default_factory` through to the field model.&lt;/p&gt;
&lt;p&gt;**Sinks — `extras` → generated Python expression**:&lt;/p&gt;
&lt;p&gt;1. `src/datamodel_code_generator/model/pydantic_base.py:222-249`:&lt;/p&gt;
&lt;p&gt;```python
   default_factory = data.pop(&amp;#34;default_factory&amp;#34;, None)
   ...
   if default_factory is not None:
       field_arguments…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-386q-5hp3-95m9</guid>
    </item>
    <item>
      <title>PYSEC-2026-3555 — `datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3555</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`datamodel-code-generator` is vulnerable to code injection when generating Python models from an attacker-controlled JSON Schema, OpenAPI, YAML, JSON, Avro, Protobuf, or XSD schema. When a property carries a `&amp;#34;default_factory&amp;#34;` key, its value is interpolated verbatim — as a raw Python expression — into the generated `Field(default_factory=...)` / `field(default_factory=...)` call. Because this assignment is evaluated at class-definition time (i.e. on `import` of the generated module), an attacker who controls the schema controls a Python expression that runs in the consumer&amp;#39;s process. No special CLI flags are required.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable chain spans the JSON-Schema-shaped parser and three sink locations (Pydantic v2, dataclass, msgspec):&lt;/p&gt;
&lt;p&gt;**Source — schema → `extras`**:&lt;/p&gt;
&lt;p&gt;- `src/datamodel_code_generator/parser/jsonschema.py:600-614` — `DEFAULT_FIELD_KEYS` includes the literal string `&amp;#34;default_factory&amp;#34;`.
- `src/datamodel_code_generator/parser/jsonschema.py:457-459` — `JsonSchemaObject.__init__` stores any non-standard key (including `default_factory`) in `self.extras`.
- `src/datamodel_code_generator/parser/jsonschema.py:797-812` — `get_field_extras` preserves `default_factory` through to the field model.&lt;/p&gt;
&lt;p&gt;**Sinks — `extras` → generated Python expression**:&lt;/p&gt;
&lt;p&gt;1. `src/datamodel_code_generator/model/pydantic_base.py:222-249`:&lt;/p&gt;
&lt;p&gt;```python
   default_factory = data.pop(&amp;#34;default_factory&amp;#34;, None)
   ...
   if default_factory is not None:
       field_arguments…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`datamodel-code-generator` is vulnerable to code injection when generating Python models from an attacker-controlled JSON Schema, OpenAPI, YAML, JSON, Avro, Protobuf, or XSD schema. When a property carries a `&amp;#34;default_factory&amp;#34;` key, its value is interpolated verbatim — as a raw Python expression — into the generated `Field(default_factory=...)` / `field(default_factory=...)` call. Because this assignment is evaluated at class-definition time (i.e. on `import` of the generated module), an attacker who controls the schema controls a Python expression that runs in the consumer&amp;#39;s process. No special CLI flags are required.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The vulnerable chain spans the JSON-Schema-shaped parser and three sink locations (Pydantic v2, dataclass, msgspec):&lt;/p&gt;
&lt;p&gt;**Source — schema → `extras`**:&lt;/p&gt;
&lt;p&gt;- `src/datamodel_code_generator/parser/jsonschema.py:600-614` — `DEFAULT_FIELD_KEYS` includes the literal string `&amp;#34;default_factory&amp;#34;`.
- `src/datamodel_code_generator/parser/jsonschema.py:457-459` — `JsonSchemaObject.__init__` stores any non-standard key (including `default_factory`) in `self.extras`.
- `src/datamodel_code_generator/parser/jsonschema.py:797-812` — `get_field_extras` preserves `default_factory` through to the field model.&lt;/p&gt;
&lt;p&gt;**Sinks — `extras` → generated Python expression**:&lt;/p&gt;
&lt;p&gt;1. `src/datamodel_code_generator/model/pydantic_base.py:222-249`:&lt;/p&gt;
&lt;p&gt;```python
   default_factory = data.pop(&amp;#34;default_factory&amp;#34;, None)
   ...
   if default_factory is not None:
       field_arguments…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3555</guid>
    </item>
  </channel>
</rss>
