Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-107377: CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator

CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator Vulnerability ID: CVE-2026-107377 CVSS Score: 7.5 Published: 2026-10-08 A path traversal vulner

CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator

Vulnerability ID: CVE-2026-107377
CVSS Score: 7.5
Published: 2026-10-08

A path traversal vulnerability in datamodel-code-generator allows remote attackers to write or overwrite arbitrary files on the local host filesystem via a manipulated Protobuf schema containing malicious weak import paths.

TL;DR

Unsafe pathname concatenation using python's pathlib division (/) operator allows unauthenticated remote attackers to write or overwrite files outside the sandbox by supplying a crafted Protobuf schema.

Technical Details

  • CWE ID: CWE-22 / CWE-73
  • Attack Vector: Network (AV:N)
  • CVSS v3.1: 7.5 (High)
  • Impact: High Integrity Compromise (File Overwrite)
  • Exploit Status: Proof of Concept available in tests
  • KEV Status: Not listed

Affected Systems

  • datamodel-code-generator
  • datamodel-code-generator: >= 0.59.0, < 0.81.0 (Fixed in: 0.81.0)

Code Analysis

Commit: 5e94b8f

Fix: Prevent path traversal in protobuf parser

Mitigation Strategies

  • Upgrade datamodel-code-generator to version 0.81.0 or higher.
  • Isolate the code generation process in an unprivileged, read-only container environment.
  • Filter incoming .proto files to reject schemas containing relative pathing or absolute references in 'import weak' statements.

Remediation Steps:

  1. Identify all deployment instances running datamodel-code-generator versions prior to 0.81.0.
  2. Update dependencies in requirements.txt or pyproject.toml to enforce 'datamodel-code-generator>=0.81.0'.
  3. Deploy the updated application and verify that validation fails when encountering weak imports pointing outside the workspace.
  4. Configure the underlying container or execution host to run the generation service with minimal system privileges.

References

Read the full report for CVE-2026-107377 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.