CVE-2026-107377

Source
https://cve.org/CVERecord?id=CVE-2026-107377
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107377.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107377
Aliases
Published
2026-10-08T17:55:22Z
Modified
2026-10-09T02:49:56Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory
Details

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_missing_weak_imports in src/datamodel_code_generator/parser/protobuf.py. Exploitation requires a victim or automated job to process the attacker-controlled schema with Protobuf input support, which requires the grpcio-tools package. The paths escape the weak_imports temporary directory before protoc runs, allowing creation of directory trees and new files or overwrite of existing writable files with a generated Protobuf syntax declaration. The effect persists when later Protobuf compilation fails. The written content is limited to a proto2 or proto3 syntax declaration, and direct arbitrary code execution has not been demonstrated. This issue is fixed in version 0.81.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-22",
        "CWE-73"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107377.json"
}
References

Affected packages

Git / github.com/datamodel-code-generator/datamodel-code-generator

Affected ranges

Type
GIT
Repo
https://github.com/datamodel-code-generator/datamodel-code-generator
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0.59.0"
        },
        {
            "fixed": "0.81.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.59.0
0.59.1
0.60.0
0.60.1
0.60.2
0.61.0
0.62.0
0.63.0
0.64.0
0.64.1
0.65.0
0.65.1
0.66.0
0.66.1
0.66.2
0.66.3
0.67.0
0.68.0
0.68.1
0.69.0
0.70.0
0.71.0
0.72.0
0.72.1
0.72.2
0.72.3
0.72.4
0.73.0
0.74.0
0.75.0
0.75.1
0.76.0
0.76.1
0.76.2
0.77.0
0.78.0
0.79.0
0.80.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107377.json"