What is CVE-2026-54655?
This vulnerability affects datamodel-code-generator versions 0.51.0 to 0.60.2. Insufficient validation of `x-python-type` values in the JSONSchema parser allows an attacker to inject arbitrary annotations into generated Python code via a crafted schema. Users should upgrade to a version newer than 0.60.2.
Azərbaycanca: Bu boşluq datamodel-code-generator alətinin 0.51.0–0.60.2 versiyalarına təsir edir. JSONSchema parser-də `x-python-type` dəyərlərinin yetərsiz validasiyası səbəbindən təcavüzkar xüsusi hazırlanmış sxem təqdim edərək generasiya olunan Python koduna ixtiyari annotasiya daxil edə bilər. İstifadəçilərə 0.60.2-dən yuxarı versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
Which versions of datamodel-code-generator are vulnerable to CVE-2026-54655?
This vulnerability affects datamodel-code-generator versions 0.51.0 to 0.60.2.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.