CVE-2026-107377: CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator
CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator Vulnerability ID: CVE-2026-107377 CVSS Score: 7.5 Published: 2026-10-08 A path traversal vulner
CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator
Vulnerability ID: CVE-2026-107377
CVSS Score: 7.5
Published: 2026-10-08
A path traversal vulnerability in datamodel-code-generator allows remote attackers to write or overwrite arbitrary files on the local host filesystem via a manipulated Protobuf schema containing malicious weak import paths.
TL;DR
Unsafe pathname concatenation using python's pathlib division (/) operator allows unauthenticated remote attackers to write or overwrite files outside the sandbox by supplying a crafted Protobuf schema.
Technical Details
- CWE ID: CWE-22 / CWE-73
- Attack Vector: Network (AV:N)
- CVSS v3.1: 7.5 (High)
- Impact: High Integrity Compromise (File Overwrite)
- Exploit Status: Proof of Concept available in tests
- KEV Status: Not listed
Affected Systems
- datamodel-code-generator
-
datamodel-code-generator: >= 0.59.0, < 0.81.0 (Fixed in:
0.81.0)
Code Analysis
Commit: 5e94b8f
Fix: Prevent path traversal in protobuf parser
Mitigation Strategies
- Upgrade datamodel-code-generator to version 0.81.0 or higher.
- Isolate the code generation process in an unprivileged, read-only container environment.
- Filter incoming .proto files to reject schemas containing relative pathing or absolute references in 'import weak' statements.
Remediation Steps:
- Identify all deployment instances running datamodel-code-generator versions prior to 0.81.0.
- Update dependencies in requirements.txt or pyproject.toml to enforce 'datamodel-code-generator>=0.81.0'.
- Deploy the updated application and verify that validation fails when encountering weak imports pointing outside the workspace.
- Configure the underlying container or execution host to run the generation service with minimal system privileges.
References
Read the full report for CVE-2026-107377 on our website for more details including interactive diagrams and full exploit analysis.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.