Oct 8, 2026·5 min read·5 visits
Unsafe pathname concatenation using python's pathlib division (/) operator allows unauthenticated remote attackers to write or overwrite files outside the sandbox by supplying a crafted Protobuf schema.
A path traversal vulnerability in datamodel-code-generator allows remote attackers to write or overwrite arbitrary files on the local host filesystem via a manipulated Protobuf schema containing malicious weak import paths.
datamodel-code-generator is a utility designed to automate the creation of Python data representations. The module supports a broad range of ingestion formats including JSON Schema, OpenAPI, and Protocol Buffers. It translates these schemas into fully structured Pydantic models or dataclasses.
From version 0.59.0 up to 0.80.0, the library exhibits a significant vulnerability within its Protocol Buffer parsing engine. The vulnerability is located inside the file src/datamodel_code_generator/parser/protobuf.py which is responsible for managing missing dependencies during compilation. Unsanitized user inputs processed through this parser can result in severe file system manipulation.
The attack surface is exposed whenever the engine accepts untrusted .proto schemas from external actors. If an ingestion service utilizes this package without robust input filtering, remote attackers can compromise file system integrity. This vulnerability is tracked as CVE-2026-107377 and GHSA-77xj-x4rm-935c.
The underlying flaw resides in how the ProtobufParser class prepares weak import structures for the Protocol Compiler (protoc). To allow compilation to succeed even when imported models are missing, the parser extracts dependencies declared via import weak statements. It identifies these paths using a regular expression and attempts to generate dummy files within an isolated sandbox.
During file system path generation, the parser leverages Python's pathlib.Path class and its / division operator to concatenate the sandbox path with the extracted import path. However, the parser fails to validate whether the resulting pathname points inside the designated directory boundaries. The division operator behaves unsafely when combined with absolute paths or relative path climbing sequences.
If the import weak statement contains an absolute path, the pathlib engine completely discards the prefix representing the temporary sandbox directory. If the import path contains relative elements such as ../../, the operator appends them literally, allowing the resulting path to climb above the sandbox. The application then automatically invokes mkdir(parents=True, exist_ok=True) and write_text() on the resolved path, leading to arbitrary directory generation and file writes.
Reviewing the vulnerable code in _write_missing_weak_imports highlights the precise execution path leading to the flaw. The original implementation extracted the matched paths and performed a simple check before creating the stub files.
# Vulnerable implementation snippet
for import_path in WEAK_IMPORT_PATTERN.findall(text):
if any((include_path / import_path).exists() for include_path in include_paths):
continue
stub = self.weak_import_dir / import_path
stub.parent.mkdir(parents=True, exist_ok=True)
stub.write_text(syntax, encoding=self.parser.encoding)In this logic, if import_path contains directory climbing directives, the resulting stub object points to an arbitrary location outside self.weak_import_dir. Additionally, the existing file validation check uses include_path / import_path. Because this check evaluates a different destination than the one actually written to, it fails to flag and prevent the overwrite of sensitive destination targets.
The remediation introduces a defensive check using resolve() alongside is_relative_to(). The resolution step normalizes the relative segments, and the subsequent check guarantees that the path resides strictly inside the temporary workspace.
# Patched implementation snippet
weak_import_dir = self.weak_import_dir.resolve()
for import_path in WEAK_IMPORT_PATTERN.findall(text):
stub = (weak_import_dir / import_path).resolve()
if not stub.is_relative_to(weak_import_dir):
msg = f"Invalid Protocol Buffers weak import path: {import_path!r}"
raise SchemaParseError(msg)
# Remaining safe write logic continues...An attacker can trigger this vulnerability by submitting a Protocol Buffer schema containing a specifically formatted weak import path. The attack does not require any specialized tools or complex configuration flags. A standard .proto schema file is sufficient to execute the traversal.
syntax = "proto3";
import weak "../../../../tmp/target_configuration.json";
message TraversalMessage {
string payload = 1;
}When the parser ingests this file, it extracts ../../../../tmp/target_configuration.json and evaluates it against the base directory. The file system creates any intermediate directories that do not exist, and subsequently executes a write command. It populates the targeted file with the text string syntax = "proto3";.
The write operation persists even if the overall compilation fails. Because the parser prepares these dummy files prior to running the actual protoc compiler, any subsequent syntax errors within the schema do not revert the file modification. This behavior allows attackers to manipulate configuration files, overwrite script files, or crash running processes by corrupting their data formats.
The direct impact of CVE-2026-107377 is classified as a high integrity compromise. An unauthenticated remote attacker can corrupt or overwrite files across any directory where the process owns write permissions. Since the generator often operates as part of an automated pipeline, it may possess privileges to modify application resources.
While the vulnerability does not directly expose contents of the filesystem, it represents a significant vector for service disruption. By overwriting configuration assets, an attacker can trigger application instability or denial of service. Under specific conditions, writing arbitrary content into executable directories can facilitate remote execution.
The severity of this flaw is compounded by the ease of exploitation. The attack complexity is low, requiring nothing more than a standard schema submission. Systems that process third-party schemas automatically are highly vulnerable to this exploitation strategy.
The primary remediation strategy is upgrading datamodel-code-generator to version 0.81.0 or higher. This release integrates the validation checks that prevent paths from escaping the temporary boundary. It also introduces automatic cleanup routines that remove the temporary directory if validation fails during parser execution.
If upgrading is not immediately feasible, teams must implement alternative defensive configurations. Schema ingestion endpoints should be restricted to authenticated users. Input validators should check incoming files for the presence of the import weak directive and block any files containing path traversal sequences.
As a general security practice, running the generator inside an isolated sandbox container minimizes the overall blast radius. Configuring the execution environment with a read-only root file system prevents the parser from writing outside designated workspace folders. These multi-layered boundaries ensure that directory traversal attempts do not affect system resources.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
datamodel-code-generator datamodel-code-generator | >= 0.59.0, < 0.81.0 | 0.81.0 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-22 / CWE-73 |
| Attack Vector | Network (AV:N) |
| CVSS v3.1 | 7.5 (High) |
| Impact | High Integrity Compromise (File Overwrite) |
| Exploit Status | Proof of Concept available in tests |
| KEV Status | Not listed |
The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname.
PraisonAI is vulnerable to an arbitrary local file read vulnerability prior to version 4.6.78. The flaw is in the ContextGatherer component, where validation checks are executed only after files are parsed and appended to the context bundle, bypassing security constraints.
An algorithmic complexity vulnerability (CWE-770) in the Excelize library allows remote attackers to cause resource exhaustion (100% CPU usage) via a crafted Microsoft Excel spreadsheet. This occurs because the look-ahead row index parsing in Rows.Columns() fails to enforce upper boundary limits, enabling an out-of-bounds row index to trigger an infinite seek loop inside the Rows iterator.
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.
A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.
A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.
CVE-2026-76485 is a critical stack-based buffer overflow vulnerability in the VXLAN OAM (NGOAM) parsing component of Cisco NX-OS Software. The flaw enables an unauthenticated, remote attacker to execute arbitrary code with root privileges or trigger a denial of service on affected Nexus switches. This vulnerability is triggered through crafted packets sent to an IP interface. No workarounds are currently available to mitigate the vulnerability while preserving the NGOAM functionality. Cisco has published software patches to address this flaw.