What is CVE-2026-54654?
CVE-2026-54654 affects `datamodel-code-generator` versions 0.14.1 to 0.60.2, where the `--extra-template-data` option renders unsanitized input into Python comments via the `TypeAliasAnnotation.jinja2` template. Users should update to the latest version immediately.
Azərbaycanca: CVE-2026-54654 zəifliyi `datamodel-code-generator` kitabxanasının 0.14.1-dən 0.60.2-yə qədər versiyalarına təsir edir. `--extra-template-data` parametri ilə ötürülən məlumatlar `TypeAliasAnnotation.jinja2` şablonunda Python şərhlərinə filterlənmədən daxil edilir. İstifadəçilər dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which versions of `datamodel-code-generator` are affected by CVE-2026-54654?
The vulnerability affects versions from 0.14.1 to 0.60.2.
What action should `datamodel-code-generator` users take regarding CVE-2026-54654?
Users should update to the latest version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.