A high-severity server-side request forgery flaw tracked as CVE-2026-54690 affects datamodel-code-generator when it processes attacker-controlled JSON Schema $ref values pointing to http or https URLs. In vulnerable releases, the tool silently resolves remote references during schema processing, allowing outbound requests to arbitrary destinations; one report places the affected range at 0.9.1 through 0.60.x, while another indicates exposure through 0.61.0. The issue has a CVSS v3.1 score of 8.2 and is tied to schema resolution and HTTP fetch logic in files including jsonschema.py and http.py.
Researchers said the vulnerable code passes untrusted URLs directly to the HTTP client, follows redirects, and does not adequately restrict hostnames, ports, or IP ranges, creating a path to reach internal services such as 127.0.0.1 and cloud metadata endpoints like 169.254.169.254. Fetched content may also be incorporated into generated output, raising information disclosure risk in addition to SSRF. The issue is fixed in version 0.61.0, with the patch adding URL validation and blocking localhost-style and non-global IP targets unless private-network access is explicitly enabled; recommended mitigations include disabling remote reference resolution or blocking private-network access.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-54690 was publicly reported as a high-severity SSRF vulnerability affecting datamodel-code-generator. The disclosure states that vulnerable versions process attacker-controlled remote schema references, potentially enabling requests to internal resources and information disclosure.
A server-side request forgery flaw involving remote JSON Schema $ref resolution was fixed in datamodel-code-generator 0.61.0. The fix adds protections around remote URL fetching and addresses unsafe default handling of attacker-controlled HTTP or HTTPS references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.