datamodel-code-generator Package Vulnerable to Code Injection
EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-386Q-5HP3-95M9Severity: HIGH
The datamodel-code-generator package is reportedly vulnerable to code injection when generating Python models from an attacker-controlled schema.
What happened
An attacker can control a Python expression that runs in the consumer's process. This vulnerability appears to affect versions from 0.17.0 to 0.60.2, with some exceptions. The issue is under investigation and a patched version is expected. Engineers using this package should review any generated code for potential injection and be prepared to upgrade once a fix is available.
How 0Day mitigates this
MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If
datamodel-code-generator is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.