Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-77xj-x4rm-935c | datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory |
Thu, 08 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.81.0, an attacker-controlled Protobuf schema can supply absolute or parent-directory paths captured by WEAK_IMPORT_PATTERN and consumed by _write_missing_weak_imports in src/datamodel_code_generator/parser/protobuf.py. Exploitation requires a victim or automated job to process the attacker-controlled schema with Protobuf input support, which requires the grpcio-tools package. The paths escape the weak_imports temporary directory before protoc runs, allowing creation of directory trees and new files or overwrite of existing writable files with a generated Protobuf syntax declaration. The effect persists when later Protobuf compilation fails. The written content is limited to a proto2 or proto3 syntax declaration, and direct arbitrary code execution has not been demonstrated. This issue is fixed in version 0.81.0. | |
| Title | datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory | |
| Weaknesses | CWE-22 CWE-73 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T17:55:22.595Z
Reserved: 2026-10-07T21:07:54.987Z
Link: CVE-2026-107377
No data.
Status : Deferred
Published: 2026-10-08T18:17:22.973
Modified: 2026-10-08T18:17:23.367
Link: CVE-2026-107377
No data.
OpenCVE Enrichment
No data.
Github GHSA