PT-2026-108124 · Datamodel Code Generator+2 · Datamodel-Code-Generator
CVE-2026-107377
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Summary
When processing an attacker-controlled Protobuf schema, vulnerable versions of
datamodel-code-generator could write a generated weak-import stub outside the
intended weak imports temporary directory. Absolute import paths and relative
paths containing .. could escape this directory.An attacker could create directories and new files at locations writable by the
process. Relative path traversal could also overwrite existing writable files
because the existence check and the stub write used different base directories.
An existing absolute target was skipped by the existence check.
Written content was limited to a generated Protobuf syntax declaration,
syntax = "proto2"; or syntax = "proto3";, followed by a newline. This issue did
not provide fully attacker-controlled file contents, and direct arbitrary code
execution has not been demonstrated.These filesystem side effects occurred before
protoc ran. A subsequent
compilation error did not undo them. A user or CI job must process the
attacker-controlled schema for the issue to be triggered, whether the schema is
supplied as a local file or fetched via --url.The fix has been merged into the parent repository's
main branch in
5e94b8f. A patched package release is not yet available.
The technical details and PoC below describe the vulnerable implementation before
that fix.Affected component
- Repository:
datamodel-code-generator/datamodel-code-generator(formerlykoxudaxi/datamodel-code-generator). - Analyzed at: released 0.80.0 (
pip install datamodel-code-generator==0.80.0) andmain@ commit834731d56c0a90c182a0919f316069cf5ff0659a(2026-09-13). Both contained the identical vulnerable sink. - Sink / entry point (
src/datamodel code generator/parser/protobuf.py, line numbers from 0.80.0): - Source:
WEAK IMPORT PATTERN(protobuf.py:37) — attacker-controlled capture group. - Sink:
write missing weak imports(protobuf.py:391-393) —weak import dir / import path+mkdir(parents=True)+write text. - Timing: called from
ProtoInputPreparer. enter(protobuf.py:333), beforeprotoc.main(...)runs inside thewithbody. - Preconditions: victim runs the tool (CLI or Python API) with
--input-file-type protobufon an attacker-controlled.proto, supplied as a local file (--input) or a remote URL (--url). Requires thegrpcio-toolspackage (Protobuf support). The attacker does not need privileges on the affected system; filesystem effects are limited to locations writable by the code-generation process.
Severity
Proposed: High.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N = 7.5.- Scored to match the project's own rating of the sibling path-traversal advisories CVE-2026-55389 / CVE-2026-55390, both
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N= 7.5. This finding is the same attack surface (unvalidated path from a processed schema) with the impact moved from confidentiality (read) to integrity (write), henceC:N/I:H. AV:N: the malicious schema can be fetched over the network via--url, consistent with how the siblings were scored.I:H: attacker fully controls the write path and can create arbitrary directory trees and overwrite existing files; only the file content is constrained (a fixedsyntax = "proto{2,3}";line).A:Nchosen conservatively; overwriting build-critical files (lock files,init .py, entry points) can cause availability loss, which would argueA:L.- Honest alternative: if the reviewer treats "the victim must run the tool on the file" as user interaction (
UI:R), the score is 6.5 (Moderate). The project usedUI:Nfor the identical read-path siblings, soUI:Nis used here for consistency.
Details
Source pattern — the imported path is captured with no character restriction:
python
# protobuf.py:37
WEAK IMPORT PATTERN = re.compile(r'^s*imports+weaks+"([^"]+)"s*;', re.MULTILINE)Sink — the captured path is joined and written with no boundary check:
python
# protobuf.py:383-393 ( write missing weak imports)
for import path in WEAK IMPORT PATTERN.findall(text):
if any((include path / import path).exists() for include path in include paths):
continue
stub = self.weak import dir / import path # no resolve(), no is relative to()
stub.parent.mkdir(parents=True, exist ok=True) # arbitrary directory tree
stub.write text(syntax, encoding=self.parser.encoding)Two escape mechanisms, both from
pathlib's / semantics:- Absolute path:
Path(".../ weak imports ") / "/etc/x"==/etc/x(an absolute right operand replaces the base). Creates new files anywhere the process can write. ../traversal:Path(".../ weak imports ") / "../../x"climbs out of the temp directory.
Why the existence guard (line 389) does not protect the write: it checks
include path / import path, using a different base (include paths) than the
actual write, which uses self.weak import dir / import path. For a relative
path the two bases resolve to different directories, so the guard checks a location
that is not the real write target and misses it — enabling overwrite of existing
files. (For an absolute path the guard and the write coincide, so an already-
existing absolute target is skipped; absolute paths thus create new files but do not
overwrite. Overwrite is reached via the relative-traversal path.)Timing:
write missing weak imports runs inside enter (line 333), and
protoc.main(...) runs later in the with body. protoc rejects the malformed
virtual path (Backslashes, consecutive slashes, "." or ".." are not allowed in the virtual path) and the overall command exits non-zero — but the file has
already been written; the filesystem side effect is not rolled back.Attack path
- Attacker crafts
evil.protocontaining e.g.import weak "/home/victim/.config/x";and/orimport weak "../../overwrite me.txt";, and gets the victim to process it (third-party schema, or--urlto an attacker-hosted file). write missing weak importswrites the stub to the attacker-chosen path, creating any intermediate directories and overwriting an existing file (relative case).protocthen fails, but the file(s) are already on disk.
Proof of Concept
Two self-contained scripts (
poc/reproduce.sh for --input, poc/reproduce-url.sh
for --url) install the released datamodel-code-generator==0.80.0, serve/point a
malicious .proto, and assert the writes. The PoC drives the released package
unmodified; the sink file's sha256 is recorded in REPRODUCE.md.Local
--input run against 0.80.0 — real output:[*] installed version: 0.80.0
[test A] absolute-path arbitrary file + mkdir(parents):
[PASS] new file created at attacker-controlled absolute path
[PASS] content is the fixed syntax stub
[test B] relative-traversal overwrite of pre-existing file:
[PASS] pre-existing victim.txt content was overwritten
[PASS] victim.txt now holds the injected stub
==================== RESULT: 4 passed, 0 failed ====================Remote
--url run against 0.80.0 — real output (proto served over HTTP, then the
same writes fire):[*] serving malicious proto at http://127.0.0.1:<port>/evil url.proto
[PASS] server actually served the proto (HTTP 200)
[PASS] absolute-path arbitrary file created
[PASS] pre-existing victim overwritten via ../
==================== RESULT: 3 passed, 0 failed ====================Impact
Any user or CI pipeline that runs an affected version of
datamodel-code-generator on an untrusted
Protobuf schema (a downloaded third-party .proto, or --url to a remote source)
is exposed to arbitrary file/directory creation and overwrite by the schema author,
with the process's own permissions. Concrete harms:- Overwrite source, config,
.env, lock files, orinit .py/ entry-point files → project corruption, broken builds, denial of service. - Create arbitrary directory trees / drop files into watched or auto-loaded locations.
Direct arbitrary code execution has not been demonstrated. The written content
is limited to a generated
syntax = "proto2"; or syntax = "proto3"; line and is
not fully attacker-controlled.Resolution
The fix was merged into the parent repository's
main branch in
5e94b8f.The Protobuf input preparer now resolves the dedicated temporary weak-import
directory and each candidate stub path. If a resolved candidate is outside that
directory, it raises
SchemaParseError before checking include paths, creating
parent directories, or writing the stub. The containment check rejects
absolute-path escapes and relative .. traversal that would leave the sandbox.Input-preparation failures also immediately clean up the temporary directory.
Regression tests cover:
- rejection of absolute weak-import paths outside the sandbox;
- rejection of relative
..traversal outside the sandbox; - preservation of a pre-existing file outside the sandbox.
Local tox validation of the patch passed across the Python 3.10–3.14 and formatter
matrix, the CI compatibility environments, and the repository checks. Combined
line and branch coverage, including the changed files, reached 100%.
A fixed package has not yet been published to PyPI; the latest published version
at the time of this update is 0.80.0.
Patched versions remains unset until a
release containing this fix is available. The advisory remains private pending
that release.References
- GHSA-8359-h9fx-j6v9 / CVE-2026-55389 — datamodel-code-generator arbitrary local file read via JSON-Schema
$refpath traversal (CWE-22/200/610, 7.5, patched 0.62.0). Same class, read primitive; sibling entry point. - GHSA-442q-2j6p-642g / CVE-2026-55390 — datamodel-code-generator arbitrary local file read via XSD
schemaLocationpath traversal (CWE-22/200/610, 7.5, affected>= 0.59.0, <= 0.61.0, patched 0.62.0). Same class, read primitive; the fix sweep that missed the Protobuf entry point. - Python
pathlib—PurePath. truediv: an absolute right-hand operand discards the left operand;..segments are not normalized. (https://docs.python.org/3/library/pathlib.html)
Discovery
Found via source review and a reproducing PoC on
datamodel-code-generator/datamodel-code-generator, released 0.80.0 and main @
834731d56c0a90c182a0919f316069cf5ff0659a, 2026-09.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Datamodel-Code-Generator