CVE-2026-63720EPSS p52.9%
CVE-2026-63720CVE-2026-63720
Description
datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is emitted verbatim into a generated 'from ... import ...' statement without identifier validation, causing arbitrary Python code to execute when the generated module is imported.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 0.74% probability of exploitation · percentile 52.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-08-12 |