What is CVE-2026-55390?
CVE-2026-55390 is a vulnerability in the datamodel-code-generator tool versions 0.59.0 through 0.62.0, where parsing XML Schema files insecurely handles `schemaLocation` attributes from `xs:include`, `xs:import`, `xs:redefine`, and `xs:override` elements, potentially allowing unauthorized file operations. Attackers could exploit this with crafted XML schema files to read unexpected server resources. Immediate upgrade beyond version 0.62.0 is recommended.
Azərbaycanca: CVE-2026-55390, datamodel-code-generator alətinin 0.59.0-dən 0.62.0-ə qədər versiyalarında XML Schema fayllarının işlənməsi zamanı `xs:include`, `xs:import`, `xs:redefine` və `xs:override` elementlərinin `schemaLocation` atributlarının təhlükəli şəkildə işlənərək icazəsiz fayl əməliyyatlarına səbəb ola biləcəyi bir zəiflikdir. Bu, təcavüzkarın xüsusi hazırlanmış XML sxem faylları vasitəsilə serverdən gözlənilməz resursları oxumasına imkan yarada bilər. Təsirə məruz qalan sistemlərin dərhal 0.62.0 versiyasından daha yuxarıya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions are affected by CVE-2026-55390?
This vulnerability affects datamodel-code-generator versions 0.59.0 through 0.62.0.
How can CVE-2026-55390 be mitigated?
Affected systems should be immediately upgraded to a version beyond 0.62.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.