CVE-2026-63720 is a code injection vulnerability in datamodel-code-generator prior to version 0.70.0. When an attacker can control input schemas, they can supply a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The vulnerable generator emits this value verbatim into a generated Python 'from ... import ...' statement without validating that the value is a safe identifier or import path. As a result, arbitrary Python code can be injected into the generated module and will execute when that generated module is later imported, leading to remote code execution in environments that process untrusted schemas.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact proof-of-concept exploit for CVE-2026-63720, a code injection flaw in datamodel-code-generator before 0.70.0. The repo contains three files: a detailed README describing the vulnerability and impact, attacker/attack.json containing a malicious JSON Schema, and server/victim_service.py implementing a demo vulnerable HTTP service. The exploit capability is arbitrary Python code execution by abusing the schema field customBasePath. The malicious schema injects newline-separated Python into generated source so that when datamodel-code-generator emits and the victim imports generated_models.py, the injected code runs immediately. In the included payload, Python calls os.system to execute shell commands, display a marker, run whoami, and write output to RCE_PROOF.txt. The victim service demonstrates the network-service attack path described in the README. It listens unauthenticated on 127.0.0.1:8000, accepts POST bodies as schemas, writes them to client_schema.json, invokes datamodel-codegen.exe to generate generated_models.py, and then imports that file with importlib. That import step is the execution sink that turns schema injection into host command execution. Repository structure and purpose: - README.md: advisory-style documentation, affected versions, impact, references, and explanation of the vulnerable code path. - attacker/attack.json: the actual exploit input, crafted as a malicious JSON Schema with injected customBasePath content. - server/victim_service.py: runnable vulnerable demo service showing end-to-end exploitation over HTTP. This is a real exploit PoC rather than a detector. It is operational but not heavily weaponized: the payload is hardcoded, the service is a local demo, and there is no generalized attacker client or payload customization logic included.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.