CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-107377

CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 8, 2026·5 min read·5 visits

Executive Summary (TL;DR)

Unsafe pathname concatenation using python's pathlib division (/) operator allows unauthenticated remote attackers to write or overwrite files outside the sandbox by supplying a crafted Protobuf schema.

A path traversal vulnerability in datamodel-code-generator allows remote attackers to write or overwrite arbitrary files on the local host filesystem via a manipulated Protobuf schema containing malicious weak import paths.

Vulnerability Overview

datamodel-code-generator is a utility designed to automate the creation of Python data representations. The module supports a broad range of ingestion formats including JSON Schema, OpenAPI, and Protocol Buffers. It translates these schemas into fully structured Pydantic models or dataclasses.

From version 0.59.0 up to 0.80.0, the library exhibits a significant vulnerability within its Protocol Buffer parsing engine. The vulnerability is located inside the file src/datamodel_code_generator/parser/protobuf.py which is responsible for managing missing dependencies during compilation. Unsanitized user inputs processed through this parser can result in severe file system manipulation.

The attack surface is exposed whenever the engine accepts untrusted .proto schemas from external actors. If an ingestion service utilizes this package without robust input filtering, remote attackers can compromise file system integrity. This vulnerability is tracked as CVE-2026-107377 and GHSA-77xj-x4rm-935c.

Root Cause Analysis

The underlying flaw resides in how the ProtobufParser class prepares weak import structures for the Protocol Compiler (protoc). To allow compilation to succeed even when imported models are missing, the parser extracts dependencies declared via import weak statements. It identifies these paths using a regular expression and attempts to generate dummy files within an isolated sandbox.

During file system path generation, the parser leverages Python's pathlib.Path class and its / division operator to concatenate the sandbox path with the extracted import path. However, the parser fails to validate whether the resulting pathname points inside the designated directory boundaries. The division operator behaves unsafely when combined with absolute paths or relative path climbing sequences.

If the import weak statement contains an absolute path, the pathlib engine completely discards the prefix representing the temporary sandbox directory. If the import path contains relative elements such as ../../, the operator appends them literally, allowing the resulting path to climb above the sandbox. The application then automatically invokes mkdir(parents=True, exist_ok=True) and write_text() on the resolved path, leading to arbitrary directory generation and file writes.

Code Analysis

Reviewing the vulnerable code in _write_missing_weak_imports highlights the precise execution path leading to the flaw. The original implementation extracted the matched paths and performed a simple check before creating the stub files.

# Vulnerable implementation snippet
for import_path in WEAK_IMPORT_PATTERN.findall(text):
    if any((include_path / import_path).exists() for include_path in include_paths):
        continue
    stub = self.weak_import_dir / import_path
    stub.parent.mkdir(parents=True, exist_ok=True)
    stub.write_text(syntax, encoding=self.parser.encoding)

In this logic, if import_path contains directory climbing directives, the resulting stub object points to an arbitrary location outside self.weak_import_dir. Additionally, the existing file validation check uses include_path / import_path. Because this check evaluates a different destination than the one actually written to, it fails to flag and prevent the overwrite of sensitive destination targets.

The remediation introduces a defensive check using resolve() alongside is_relative_to(). The resolution step normalizes the relative segments, and the subsequent check guarantees that the path resides strictly inside the temporary workspace.

# Patched implementation snippet
weak_import_dir = self.weak_import_dir.resolve()
for import_path in WEAK_IMPORT_PATTERN.findall(text):
    stub = (weak_import_dir / import_path).resolve()
    if not stub.is_relative_to(weak_import_dir):
        msg = f"Invalid Protocol Buffers weak import path: {import_path!r}"
        raise SchemaParseError(msg)
    # Remaining safe write logic continues...

Exploitation Methodology

An attacker can trigger this vulnerability by submitting a Protocol Buffer schema containing a specifically formatted weak import path. The attack does not require any specialized tools or complex configuration flags. A standard .proto schema file is sufficient to execute the traversal.

syntax = "proto3";
import weak "../../../../tmp/target_configuration.json";
 
message TraversalMessage {
    string payload = 1;
}

When the parser ingests this file, it extracts ../../../../tmp/target_configuration.json and evaluates it against the base directory. The file system creates any intermediate directories that do not exist, and subsequently executes a write command. It populates the targeted file with the text string syntax = "proto3";.

The write operation persists even if the overall compilation fails. Because the parser prepares these dummy files prior to running the actual protoc compiler, any subsequent syntax errors within the schema do not revert the file modification. This behavior allows attackers to manipulate configuration files, overwrite script files, or crash running processes by corrupting their data formats.

Impact Assessment

The direct impact of CVE-2026-107377 is classified as a high integrity compromise. An unauthenticated remote attacker can corrupt or overwrite files across any directory where the process owns write permissions. Since the generator often operates as part of an automated pipeline, it may possess privileges to modify application resources.

While the vulnerability does not directly expose contents of the filesystem, it represents a significant vector for service disruption. By overwriting configuration assets, an attacker can trigger application instability or denial of service. Under specific conditions, writing arbitrary content into executable directories can facilitate remote execution.

The severity of this flaw is compounded by the ease of exploitation. The attack complexity is low, requiring nothing more than a standard schema submission. Systems that process third-party schemas automatically are highly vulnerable to this exploitation strategy.

Remediation and Mitigation

The primary remediation strategy is upgrading datamodel-code-generator to version 0.81.0 or higher. This release integrates the validation checks that prevent paths from escaping the temporary boundary. It also introduces automatic cleanup routines that remove the temporary directory if validation fails during parser execution.

If upgrading is not immediately feasible, teams must implement alternative defensive configurations. Schema ingestion endpoints should be restricted to authenticated users. Input validators should check incoming files for the presence of the import weak directive and block any files containing path traversal sequences.

As a general security practice, running the generator inside an isolated sandbox container minimizes the overall blast radius. Configuring the execution environment with a read-only root file system prevents the parser from writing outside designated workspace folders. These multi-layered boundaries ensure that directory traversal attempts do not affect system resources.

Official Patches

datamodel-code-generatorFix: Prevent path traversal in protobuf parser

Fix Analysis (1)

Technical Appendix

CVSS Score
7.5/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected Systems

datamodel-code-generator

Affected Versions Detail

Product
Affected Versions
Fixed Version
datamodel-code-generator
datamodel-code-generator
>= 0.59.0, < 0.81.00.81.0
AttributeDetail
CWE IDCWE-22 / CWE-73
Attack VectorNetwork (AV:N)
CVSS v3.17.5 (High)
ImpactHigh Integrity Compromise (File Overwrite)
Exploit StatusProof of Concept available in tests
KEV StatusNot listed

MITRE ATT&CK Mapping

T1083File and Directory Discovery
Discovery
T1005Data from Local System
Collection
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname.

Vulnerability Timeline

Security issue addressed in fix commit
2026-09-13
Vulnerability published in GitHub Advisory Database
2026-10-08
CVE-2026-107377 assigned and published in NVD
2026-10-08

References & Sources

  • [1]NVD - CVE-2026-107377
  • [2]GitHub Security Advisory GHSA-77xj-x4rm-935c
  • [3]Official Fix Patch Commit

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 2 hours ago•CVE-2026-61431
6.8

CVE-2026-61431: Arbitrary Local File Read and Path Traversal in PraisonAI ContextGatherer

PraisonAI is vulnerable to an arbitrary local file read vulnerability prior to version 4.6.78. The flaw is in the ContextGatherer component, where validation checks are executed only after files are parsed and appended to the context bundle, bypassing security constraints.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 3 hours ago•CVE-2026-107212
7.5

CVE-2026-107212: CPU Exhaustion Denial of Service via Look-Ahead Row Parsing in Excelize

An algorithmic complexity vulnerability (CWE-770) in the Excelize library allows remote attackers to cause resource exhaustion (100% CPU usage) via a crafted Microsoft Excel spreadsheet. This occurs because the look-ahead row index parsing in Rows.Columns() fails to enforce upper boundary limits, enabling an out-of-bounds row index to trigger an infinite seek loop inside the Rows iterator.

Alon Barad
Alon Barad
12 views•6 min read
•about 4 hours ago•CVE-2026-105647
4.0

CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.

Alon Barad
Alon Barad
8 views•8 min read
•about 5 hours ago•CVE-2026-106450
5.3

CVE-2026-106450: Denial of Service via Eager Resource Allocation in lz4-java LZ4FrameInputStream

A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.

Alon Barad
Alon Barad
12 views•8 min read
•about 6 hours ago•CVE-2026-106449
3.7

CVE-2026-106449: Stack Overflow via Uncontrolled Recursion in yawkat lz4-java

A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.

Alon Barad
Alon Barad
8 views•6 min read
•about 6 hours ago•CVE-2026-76485
9.8

CVE-2026-76485: Remote Code Execution in Cisco NX-OS VXLAN OAM (NGOAM)

CVE-2026-76485 is a critical stack-based buffer overflow vulnerability in the VXLAN OAM (NGOAM) parsing component of Cisco NX-OS Software. The flaw enables an unauthenticated, remote attacker to execute arbitrary code with root privileges or trigger a denial of service on affected Nexus switches. This vulnerability is triggered through crafted packets sent to an IP interface. No workarounds are currently available to mitigate the vulnerability while preserving the NGOAM functionality. Cisco has published software patches to address this flaw.

Alon Barad
Alon Barad
12 views•6 min read