A high-severity code injection vulnerability, CVE-2026-54653, affects datamodel-code-generator versions 0.17.0 through 0.60.1, allowing attacker-controlled JSON Schema input to inject unsafe default_factory values into generated Python models. When a victim later imports the generated code, the embedded Python expression can execute, creating a remotely exploitable path from untrusted schema parsing to code execution. The issue is tracked with CVSS 8.8 and mapped to CWE-94 and CWE-1336.
Project maintainers addressed the flaw in version 0.60.2, which includes fixes for this and other code-injection vectors involving schema-provided default_factory, x-python-type, comment data passed through --extra-template-data, and Pydantic v2 validator definitions supplied via --validators or --extra-template-data. The patch for default_factory now limits accepted values to an allowlist of dict, list, and set, rejecting code-like strings, lambdas, function references, and None; defenders are advised to upgrade to 0.60.2, review previously generated models for unsafe default_factory usage, and avoid importing generated code produced from untrusted schemas until updated.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Version 0.60.2 of datamodel-code-generator was released to address multiple security issues, including code injection via attacker-controlled default_factory values. The release also fixed related injection vectors involving x-python-type, comment entries from extra template data, and Pydantic v2 validator definitions.
A source code patch was committed to datamodel-code-generator to restrict schema-supplied default_factory values to an allowlist of "dict", "list", and "set", rejecting other values as unsafe. The change also added tests covering code-like strings, lambdas, function references, and None.
CVE-2026-54653 was publicly documented as a high-severity code injection vulnerability affecting datamodel-code-generator versions 0.17.0 through 0.60.1. The issue stems from preserving attacker-controlled default_factory values during JSON Schema parsing and was noted as fixed in version 0.60.2.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.