Description
datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_missing_weak_imports in src/datamodel_code_generator/parser/protobuf.py. Exploitation requires a victim or automated job to process the attacker-controlled schema with Protobuf input support, which requires the grpcio-tools package. The paths escape the weak_imports temporary directory before protoc runs, allowing creation of directory trees and new files or overwrite of existing writable files with a generated Protobuf syntax declaration. The effect persists when later Protobuf compilation fails. The written content is limited to a proto2 or proto3 syntax declaration, and direct arbitrary code execution has not been demonstrated. This issue is fixed in version 0.81.0.
Published: 2026-10-08
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Writes files outside the allowed temporary directory, potentially overwriting critical files
Action: Apply Patch
AI Analysis

Impact

An attacker can supply a Protobuf schema that contains absolute or parent-directory paths, which the datamodel-code-generator processes when weak-import support is enabled. The parser writes the resolved imports into a temporary directory that is not protected against traversal; this allows the attacker to cause files to be written or overwritten outside that temporary area. While the payload is limited to a proto2 or proto3 syntax declaration and no arbitrary code execution has been proven, the ability to create directories and files can corrupt data or facilitate further attacks downstream.

Affected Systems

Vendors involved are the datamodel-code-generator project. Versions from 0.59.0 through, and including, 0.81.0 are affected. The issue was addressed in release 0.81.0, which removes the weak-import path handling that permitted the traversal.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. No EPSS data is available, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited in the wild. Exploit requires the target to manage a Protobuf schema with weak import support and to have the grpcio-tools package installed; an automatic job or a user who can control the schema can trigger the file writes.

Generated by OpenCVE AI on October 8, 2026 at 19:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to datamodel-code-generator version 0.81.0 or later, which removes the insecure weak import handling.
  • If an upgrade cannot be performed, disable Protobuf weak-import support or uninstall the grpcio-tools package to prevent the parser from processing vulnerable schema files.
  • Ensure the temporary directory used by the tool is moved to a location with restrictive permissions and monitor the system for unexpected file creation outside expected locations to detect potential exploitation attempts.

Generated by OpenCVE AI on October 8, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-77xj-x4rm-935c datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory
History

Thu, 08 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_missing_weak_imports in src/datamodel_code_generator/parser/protobuf.py. Exploitation requires a victim or automated job to process the attacker-controlled schema with Protobuf input support, which requires the grpcio-tools package. The paths escape the weak_imports temporary directory before protoc runs, allowing creation of directory trees and new files or overwrite of existing writable files with a generated Protobuf syntax declaration. The effect persists when later Protobuf compilation fails. The written content is limited to a proto2 or proto3 syntax declaration, and direct arbitrary code execution has not been demonstrated. This issue is fixed in version 0.81.0.
Title datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory
Weaknesses CWE-22
CWE-73
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T17:55:22.595Z

Reserved: 2026-10-07T21:07:54.987Z

Link: CVE-2026-107377

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T18:17:22.973

Modified: 2026-10-08T18:17:23.367

Link: CVE-2026-107377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T19:45:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path