What is CVE-2026-63720?
CVE-2026-63720 is a code injection vulnerability in `datamodel-code-generator` versions prior to 0.70.0. Attackers who control input schemas can achieve remote code execution by supplying a malicious `customBasePath` value containing embedded newlines and a dot-free Python expression. Upgrading to version 0.70.0 or later is strongly recommended.
Azərbaycanca: CVE-2026-63720 `datamodel-code-generator`-in 0.70.0-dən əvvəlki versiyalarında aşkarlanmış code injection zəifliyidir. Təcavüzkar `customBasePath` parametrində xüsusi sətir ayırıcıları və nöqtəsiz Python ifadəsi yerləşdirərək uzaqdan kod icrasına (remote code execution) nail ola bilər. Təsirlənən sistemlərdə dərhal 0.70.0 və ya daha yeni versiyaya yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
How can an attacker exploit CVE-2026-63720 to achieve remote code execution?
By supplying a malicious `customBasePath` value containing embedded newlines and a dot-free Python expression.
Which version should be upgraded to in order to mitigate CVE-2026-63720?
Upgrading to version 0.70.0 or later is strongly recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.