_get_ref_body of the file src/datamodel_code_generator/parser/jsonschema.py of the component Json Schema Parser. Such manipulation of the argument ref leads to server-side request forgery.
This vulnerability is documented as CVE-2026-54690. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-54690 | koxudaxi datamodel-code-generator up to 0.60.x Json Schema Parser jsonschema.py _get_ref_body ref server-side request forgery
Reagiere als Erste:r — dein Feedback zählt!
A vulnerability was found in koxudaxi datamodel-code-generator up to 0.60.x. It has been declared as problematic. Impacted is the function
SOCIAL SHARE CARD GENERATOR