What is CVE-2026-54690?
CVE-2026-54690: In datamodel-code-generator versions 0.9.1 through 0.61.0, the tool silently dereferences attacker-controlled JSON Schema $ref URLs via HTTP or HTTPS. This flaw may allow remote resource inclusion during model generation. Users should upgrade to a version above 0.61.0 immediately.
Azərbaycanca: CVE-2026-54690: datamodel-code-generator 0.9.1–0.61.0 versiyalarında JSON Schema $ref linklərini susaraq HTTP/HTTPS ünvanlarından çəkən zəiflik aşkarlanıb. Bu, təcavüzkarın idarə etdiyi xarici resursları kod generasiyasına daxil edə bilməsi ilə nəticələnir. İstifadəçilər dərhal 0.61.0-dan yuxarı versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of datamodel-code-generator are affected by CVE-2026-54690?
Versions 0.9.1 through 0.61.0 are affected.
How can I protect against CVE-2026-54690?
You should immediately upgrade to a version above 0.61.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.