<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 06:32:22 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-342293</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342293</link>
      <description>EUVD-2026-342293</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342293</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55389</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55389</link>
      <description>&lt;p&gt;datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_generator/parser/jsonschema.py through is_url and _get_ref_body without containing file:// or ../ traversal references to the input directory and without honoring --no-allow-remote-refs, allowing arbitrary local file reads. This issue is fixed in version 0.62.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. Prior to 0.62.0, datamodel-code-generator resolves JSON Schema $ref targets in src/datamodel_code_generator/parser/jsonschema.py through is_url and _get_ref_body without containing file:// or ../ traversal references to the input directory and without honoring --no-allow-remote-refs, allowing arbitrary local file reads. This issue is fixed in version 0.62.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55389</guid>
    </item>
    <item>
      <title>GHSA-8359-h9fx-j6v9 — datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal)…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-8359-h9fx-j6v9</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`datamodel-code-generator` resolves JSON-Schema `$ref` targets that point at the local filesystem without restricting them to the input/base directory and without honoring the remote-reference security control. In the default configuration, an attacker who controls an input schema (a &amp;#34;paste your OpenAPI/JSON-Schema&amp;#34; service, a CI job that generates models from a submitted spec, or any multi-tenant codegen platform) can read any file the process user can read and map the host filesystem. This works via either a `file://` absolute URI or a `../`-escaped relative reference, and it succeeds even when `--no-allow-remote-refs` is set.&lt;/p&gt;
&lt;p&gt;This is an unauthenticated path-traversal / information-disclosure issue (CWE-22 / CWE-200) plus a bypass of a documented security control.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`is_url()` classifies `file://` as a URL (`reference.py:1249`):&lt;/p&gt;
&lt;p&gt;```python
def is_url(ref: str) -&amp;gt; bool:
    return ref.startswith((&amp;#34;https://&amp;#34;, &amp;#34;http://&amp;#34;, &amp;#34;file://&amp;#34;))
```&lt;/p&gt;
&lt;p&gt;The remote-ref gate then explicitly exempts `file://`, so `--no-allow-remote-refs` never applies to it (`parser/jsonschema.py`, `_get_ref_body`):&lt;/p&gt;
&lt;p&gt;```python
if is_url(resolved_ref):
    if not resolved_ref.startswith(&amp;#34;file://&amp;#34;) and self.http_local_ref_path is None:
        if self.allow_remote_refs is False:
            raise Error(...)        # &amp;lt;-- skipped for file://
        ...
    return self._get_ref_body_from_url(resolved_ref)
return self._get_ref_body_from_remote(resolved_ref)
```&lt;/p&gt;
&lt;p&gt;Both local-file branches rea…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`datamodel-code-generator` resolves JSON-Schema `$ref` targets that point at the local filesystem without restricting them to the input/base directory and without honoring the remote-reference security control. In the default configuration, an attacker who controls an input schema (a &amp;#34;paste your OpenAPI/JSON-Schema&amp;#34; service, a CI job that generates models from a submitted spec, or any multi-tenant codegen platform) can read any file the process user can read and map the host filesystem. This works via either a `file://` absolute URI or a `../`-escaped relative reference, and it succeeds even when `--no-allow-remote-refs` is set.&lt;/p&gt;
&lt;p&gt;This is an unauthenticated path-traversal / information-disclosure issue (CWE-22 / CWE-200) plus a bypass of a documented security control.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`is_url()` classifies `file://` as a URL (`reference.py:1249`):&lt;/p&gt;
&lt;p&gt;```python
def is_url(ref: str) -&amp;gt; bool:
    return ref.startswith((&amp;#34;https://&amp;#34;, &amp;#34;http://&amp;#34;, &amp;#34;file://&amp;#34;))
```&lt;/p&gt;
&lt;p&gt;The remote-ref gate then explicitly exempts `file://`, so `--no-allow-remote-refs` never applies to it (`parser/jsonschema.py`, `_get_ref_body`):&lt;/p&gt;
&lt;p&gt;```python
if is_url(resolved_ref):
    if not resolved_ref.startswith(&amp;#34;file://&amp;#34;) and self.http_local_ref_path is None:
        if self.allow_remote_refs is False:
            raise Error(...)        # &amp;lt;-- skipped for file://
        ...
    return self._get_ref_body_from_url(resolved_ref)
return self._get_ref_body_from_remote(resolved_ref)
```&lt;/p&gt;
&lt;p&gt;Both local-file branches rea…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-8359-h9fx-j6v9</guid>
    </item>
    <item>
      <title>PYSEC-2026-3558 — datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal)…</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3558</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`datamodel-code-generator` resolves JSON-Schema `$ref` targets that point at the local filesystem without restricting them to the input/base directory and without honoring the remote-reference security control. In the default configuration, an attacker who controls an input schema (a &amp;#34;paste your OpenAPI/JSON-Schema&amp;#34; service, a CI job that generates models from a submitted spec, or any multi-tenant codegen platform) can read any file the process user can read and map the host filesystem. This works via either a `file://` absolute URI or a `../`-escaped relative reference, and it succeeds even when `--no-allow-remote-refs` is set.&lt;/p&gt;
&lt;p&gt;This is an unauthenticated path-traversal / information-disclosure issue (CWE-22 / CWE-200) plus a bypass of a documented security control.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`is_url()` classifies `file://` as a URL (`reference.py:1249`):&lt;/p&gt;
&lt;p&gt;```python
def is_url(ref: str) -&amp;gt; bool:
    return ref.startswith((&amp;#34;https://&amp;#34;, &amp;#34;http://&amp;#34;, &amp;#34;file://&amp;#34;))
```&lt;/p&gt;
&lt;p&gt;The remote-ref gate then explicitly exempts `file://`, so `--no-allow-remote-refs` never applies to it (`parser/jsonschema.py`, `_get_ref_body`):&lt;/p&gt;
&lt;p&gt;```python
if is_url(resolved_ref):
    if not resolved_ref.startswith(&amp;#34;file://&amp;#34;) and self.http_local_ref_path is None:
        if self.allow_remote_refs is False:
            raise Error(...)        # &amp;lt;-- skipped for file://
        ...
    return self._get_ref_body_from_url(resolved_ref)
return self._get_ref_body_from_remote(resolved_ref)
```&lt;/p&gt;
&lt;p&gt;Both local-file branches rea…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;`datamodel-code-generator` resolves JSON-Schema `$ref` targets that point at the local filesystem without restricting them to the input/base directory and without honoring the remote-reference security control. In the default configuration, an attacker who controls an input schema (a &amp;#34;paste your OpenAPI/JSON-Schema&amp;#34; service, a CI job that generates models from a submitted spec, or any multi-tenant codegen platform) can read any file the process user can read and map the host filesystem. This works via either a `file://` absolute URI or a `../`-escaped relative reference, and it succeeds even when `--no-allow-remote-refs` is set.&lt;/p&gt;
&lt;p&gt;This is an unauthenticated path-traversal / information-disclosure issue (CWE-22 / CWE-200) plus a bypass of a documented security control.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`is_url()` classifies `file://` as a URL (`reference.py:1249`):&lt;/p&gt;
&lt;p&gt;```python
def is_url(ref: str) -&amp;gt; bool:
    return ref.startswith((&amp;#34;https://&amp;#34;, &amp;#34;http://&amp;#34;, &amp;#34;file://&amp;#34;))
```&lt;/p&gt;
&lt;p&gt;The remote-ref gate then explicitly exempts `file://`, so `--no-allow-remote-refs` never applies to it (`parser/jsonschema.py`, `_get_ref_body`):&lt;/p&gt;
&lt;p&gt;```python
if is_url(resolved_ref):
    if not resolved_ref.startswith(&amp;#34;file://&amp;#34;) and self.http_local_ref_path is None:
        if self.allow_remote_refs is False:
            raise Error(...)        # &amp;lt;-- skipped for file://
        ...
    return self._get_ref_body_from_url(resolved_ref)
return self._get_ref_body_from_remote(resolved_ref)
```&lt;/p&gt;
&lt;p&gt;Both local-file branches rea…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3558</guid>
    </item>
  </channel>
</rss>
