HIGHPyPI

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

CVE-2026-55390Published 1 week agoUpdated 1 day agoSource: OSV

Affected packages

  • datamodel-code-generator0.59.0 → 0.62.0

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.36%
EPSS percentile
28.8%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 29%.

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate | HackTribune