PatchSiren

koxudaxi CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH koxudaxi CVE published 2026-07-26

CVE-2026-63720

CVE-2026-63720 is a high severity vulnerability in datamodel-code-generator prior to version 0.70.0 that allows for remote code execution via a malicious customBasePath value. This vulnerability is caused by a code injection issue where the customBasePath value is emitted verbatim into a generated 'from ... import ...' statement without identifier validation. The vulnerability has a CVSS score of 7.5 and [truncated]