A high-severity server-side request forgery vulnerability, CVE-2026-54691, was disclosed in datamodel-code-generator, affecting versions 0.9.1 through 0.60.x. The flaw stems from the tool's HTTP fetch logic accepting user-supplied --url targets and redirect destinations without validating the host or IP address, allowing requests to reach localhost, loopback, private, link-local, metadata, and other non-public network resources. The issue is rated CVSS 8.2 and is considered remotely exploitable.
The project addressed the issue in version 0.61.0 with changes that block HTTP(S) requests to non-public network targets by default and validate redirect destinations before following them. The patch also introduced --allow-private-network and --no-allow-private-network options so users can explicitly opt in to trusted internal schema endpoints, while preserving public remote schema and $ref fetching behavior with warnings and updated tests, documentation, and CLI/config handling.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A June 8, 2026 commit to koxudaxi/datamodel-code-generator introduced protections against unsafe HTTP schema fetching, including blocking localhost, loopback, link-local, private, reserved, and other non-public network targets by default and validating redirect destinations before following them. The change also added a new allow-private-network option and updated related documentation and tests.
CVE-2026-54691 was disclosed as a high-severity server-side request forgery vulnerability in datamodel-code-generator affecting versions 0.9.1 up to, but not including, 0.61.0. The issue stems from accepting --url targets and redirect chain targets without host or IP validation, and the disclosure states it is fixed in version 0.61.0.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.