PatchSiren

datamodel-code-generator CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH datamodel-code-generator CVE published 2026-10-08

CVE-2026-107377

A vulnerability in `datamodel-code-generator` allows an attacker to write files outside the intended temporary directory when processing an attacker-controlled Protobuf schema. This could lead to the creation of directories and files at locations writable by the process, potentially overwriting existing files. The vulnerability is caused by a weak-import path traversal issue in `datamodel-code-generator`. [truncated]