<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 09:31:13 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-55390 — Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-55390</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; koxudaxi datamodel-code-generator&lt;/p&gt;
&lt;p&gt;datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside the input base path, allowing arbitrary local files to be read and reflected into generated models. This issue is fixed in version 0.62.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; koxudaxi datamodel-code-generator&lt;/p&gt;
&lt;p&gt;datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_generator/parser/xmlschema.py for --input-file-type xmlschema resolves xs:include, xs:import, xs:redefine, and xs:override schemaLocation values outside the input base path, allowing arbitrary local files to be read and reflected into generated models. This issue is fixed in version 0.62.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-55390</guid>
    </item>
    <item>
      <title>GHSA-442q-2j6p-642g — datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) pa…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-442q-2j6p-642g</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When generating models from an XML Schema (`--input-file-type xmlschema`), `datamodel-code-generator` resolves `&amp;lt;xs:include&amp;gt;`, `&amp;lt;xs:import&amp;gt;`, `&amp;lt;xs:redefine&amp;gt;`, and `&amp;lt;xs:override&amp;gt;` `schemaLocation` attributes against the source directory and reads the target with no restriction to the input/base directory. An attacker who controls the input XSD can read arbitrary files via `../` traversal or an absolute path, and the included schema&amp;#39;s contents (type names, restrictions, enumerations) are folded into the generated output. Unlike the JSON-Schema `$ref` path, there is no `allow_remote_refs` control for XSD, so `--no-allow-remote-refs` does not mitigate it. This is an unauthenticated path-traversal / information-disclosure issue reachable in the default configuration.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The XSD parser walks include-style children and reads each `schemaLocation` with only an `is_file()` check (`src/datamodel_code_generator/parser/xmlschema.py`):&lt;/p&gt;
&lt;p&gt;```python
location = (source_dir / schema_location).resolve()   # .resolve() collapses ../, escapes base
if location in seen or not location.is_file():
    continue
included_root = self._parse_schema(_read_xml_text(location, self.encoding), location)
```&lt;/p&gt;
&lt;p&gt;`schema_location` is attacker-controlled and `_read_xml_text` does `path.read_bytes()`. Because `(source_dir / schema_location).resolve()` normalizes `..` and accepts absolute paths, the resolved target can be any file the process can read; there is no `is_relative_to(base_path)`…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: datamodel-code-generator&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;When generating models from an XML Schema (`--input-file-type xmlschema`), `datamodel-code-generator` resolves `&amp;lt;xs:include&amp;gt;`, `&amp;lt;xs:import&amp;gt;`, `&amp;lt;xs:redefine&amp;gt;`, and `&amp;lt;xs:override&amp;gt;` `schemaLocation` attributes against the source directory and reads the target with no restriction to the input/base directory. An attacker who controls the input XSD can read arbitrary files via `../` traversal or an absolute path, and the included schema&amp;#39;s contents (type names, restrictions, enumerations) are folded into the generated output. Unlike the JSON-Schema `$ref` path, there is no `allow_remote_refs` control for XSD, so `--no-allow-remote-refs` does not mitigate it. This is an unauthenticated path-traversal / information-disclosure issue reachable in the default configuration.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;The XSD parser walks include-style children and reads each `schemaLocation` with only an `is_file()` check (`src/datamodel_code_generator/parser/xmlschema.py`):&lt;/p&gt;
&lt;p&gt;```python
location = (source_dir / schema_location).resolve()   # .resolve() collapses ../, escapes base
if location in seen or not location.is_file():
    continue
included_root = self._parse_schema(_read_xml_text(location, self.encoding), location)
```&lt;/p&gt;
&lt;p&gt;`schema_location` is attacker-controlled and `_read_xml_text` does `path.read_bytes()`. Because `(source_dir / schema_location).resolve()` normalizes `..` and accepts absolute paths, the resolved target can be any file the process can read; there is no `is_relative_to(base_path)`…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-442q-2j6p-642g</guid>
    </item>
  </channel>
</rss>
