What is CVE-2026-54691?
CVE-2026-54691 is a server-side request forgery (SSRF) vulnerability in datamodel-code-generator versions from 0.9.1 to 0.61.0, where http.get_body accepts --url targets without host/IP validation, enabling attacks against loopback, private, and link-local addresses. Users should immediately update to a patched version.
Azərbaycanca: CVE-2026-54691, datamodel-code-generator-un 0.9.1-dən 0.61.0-a qədər versiyalarında aşkarlanan server-side request forgery (SSRF) boşluğudur; http.get_body funksiyası URL target-lərini host/IP yoxlaması etmədən qəbul edir ki, bu da loopback, private və link-local ünvanlara qarşı sui-istifadəyə yol açır. Təsirə məruz qalan versiyalardan istifadə edənlər təcili olaraq yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of datamodel-code-generator are affected by CVE-2026-54691?
Versions from 0.9.1 to 0.61.0 are affected by this server-side request forgery (SSRF) vulnerability.
What is the main flaw in the http.get_body function that leads to the SSRF vulnerability?
The function accepts --url targets without host or IP validation, allowing exploitation against loopback, private, and link-local addresses.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.