Impact
An attacker can supply a Protobuf schema that contains absolute or parent-directory paths, which the datamodel-code-generator processes when weak-import support is enabled. The parser writes the resolved imports into a temporary directory that is not protected against traversal; this allows the attacker to cause files to be written or overwritten outside that temporary area. While the payload is limited to a proto2 or proto3 syntax declaration and no arbitrary code execution has been proven, the ability to create directories and files can corrupt data or facilitate further attacks downstream.
Affected Systems
Vendors involved are the datamodel-code-generator project. Versions from 0.59.0 through, and including, 0.81.0 are affected. The issue was addressed in release 0.81.0, which removes the weak-import path handling that permitted the traversal.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. No EPSS data is available, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. Exploit requires the target to manage a Protobuf schema with weak import support and to have the grpcio-tools package installed; an automatic job or a user who can control the schema can trigger the file writes.
OpenCVE Enrichment
Github GHSA