HIGH
koxudaxi
CVE published 2026-07-26
CVE-2026-63720
CVE-2026-63720 is a high severity vulnerability in datamodel-code-generator prior to version 0.70.0 that allows for remote code execution via a malicious customBasePath value. This vulnerability is caused by a code injection issue where the customBasePath value is emitted verbatim into a generated 'from ... import ...' statement without identifier validation. The vulnerability has a CVSS score of 7.5 and [truncated]