{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/datamodel-code-generator--0.70.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-63720"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["datamodel-code-generator \u003c 0.70.0"],"_cs_severities":["high"],"_cs_tags":["code-injection","rce","vulnerability"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003edatamodel-code-generator, a Python tool for generating data model code, is affected by a code injection vulnerability, CVE-2026-63720, in versions prior to 0.70.0. This flaw allows an attacker to achieve remote code execution (RCE) by manipulating input schemas. Specifically, by supplying a crafted \u003ccode\u003ecustomBasePath\u003c/code\u003e value containing embedded newlines and a dot-free Python expression, the attacker can cause arbitrary Python code to be emitted verbatim into a \u003ccode\u003efrom ... import ...\u003c/code\u003e statement within the generated module. When this compromised module is subsequently imported, the malicious Python code executes, posing a significant risk to systems that process untrusted schemas using this tool.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker prepares a malicious input schema designed for \u003ccode\u003edatamodel-code-generator\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eWithin this schema, the attacker embeds a specially crafted \u003ccode\u003ecustomBasePath\u003c/code\u003e value.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ecustomBasePath\u003c/code\u003e value includes embedded newline characters and a dot-free Python expression (e.g., \u003ccode\u003eos.system('malicious_command')\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eA legitimate user or automated system processes this malicious input schema using \u003ccode\u003edatamodel-code-generator\u003c/code\u003e prior to version 0.70.0.\u003c/li\u003e\n\u003cli\u003eDuring the code generation process, the \u003ccode\u003edatamodel-code-generator\u003c/code\u003e tool insecurely embeds the malicious \u003ccode\u003ecustomBasePath\u003c/code\u003e verbatim into a \u003ccode\u003efrom ... import ...\u003c/code\u003e statement of the output Python module without validating the identifier.\u003c/li\u003e\n\u003cli\u003eWhen an application subsequently imports this newly generated, compromised Python module, the embedded malicious Python expression is executed.\u003c/li\u003e\n\u003cli\u003eThis execution leads to remote code execution (RCE) on the system where the generated module is imported, allowing the attacker to run arbitrary commands.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63720 grants an attacker remote code execution capabilities on the system running the vulnerable \u003ccode\u003edatamodel-code-generator\u003c/code\u003e instance or any application that imports code generated from a malicious schema. This allows attackers to compromise the integrity and confidentiality of data, establish persistence, and potentially pivot to other systems within the environment. The severity of the impact depends on the privileges of the affected system, but generally represents a critical breach. No specific observed victims or targeted sectors are mentioned in the advisory, but any organization using affected versions of \u003ccode\u003edatamodel-code-generator\u003c/code\u003e to process untrusted schemas is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch \u003ccode\u003edatamodel-code-generator\u003c/code\u003e to version 0.70.0 or later immediately to remediate CVE-2026-63720.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-26T05:17:52Z","date_published":"2026-07-26T05:17:52Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-63720/","summary":"CVE-2026-63720 details a code injection vulnerability in datamodel-code-generator versions prior to 0.70.0, allowing attackers to achieve remote code execution by providing a malicious `customBasePath` value within input schemas that is unsafely embedded into a Python import statement.","title":"Code Injection Vulnerability in datamodel-code-generator (CVE-2026-63720)","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-63720/"}],"language":"en","title":"CraftedSignal Threat Feed - Datamodel-Code-Generator \u003c 0.70.0","version":"https://jsonfeed.org/version/1.1"}