What is CVE-2026-55415?
CVE-2026-55415 affects the `datamodel-code-generator` library from version 0.11.6 to 0.64.0. This vulnerability allows an attacker to execute unauthorized commands through attacker-controlled `x-python-import` or `customTypePath` schema extensions. Users should immediately update to the latest version.
Azərbaycanca: CVE-2026-55415, `datamodel-code-generator` kitabxanasının 0.11.6-dan 0.64.0-a qədər versiyalarında aşkar edilmiş boşluqdur. Bu zəiflik, təcavüzkara nəzarət etdiyi `x-python-import` və ya `customTypePath` schema genişləndirmələri vasitəsilə icazəsiz əmrlər yerinə yetirməyə imkan verir. İstifadəçilər dərhal ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which specific schema extensions are used to exploit the unauthorized command execution vulnerability in `datamodel-code-generator`?
The vulnerability is exploited through attacker-controlled `x-python-import` or `customTypePath` schema extensions.
What is the affected version range of the library vulnerable to CVE-2026-55415?
The vulnerability affects versions of the `datamodel-code-generator` library from 0.11.6 to 0.64.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.