CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54654

highCVSS 7.8covered by 2 sourcesfirst seen 2026-07-28
Summary datamodel-code-generator is vulnerable to code injection when a developer passes an --extra-template-data file whose comment value contains a literal \r (carriage return). The comment variable is rendered into a Python # comment in six built-in templates with no line-terminator escaping. Python's tokenizer treats a bare CR as a physical-line terminator (see Python language reference — Physical lines), so the comment ends at the \r and the text after it is parsed as Python, including, when the CR is followed by suitable indentation, as a statement within the class body that follows on the next template line. Details The vulnerable templates each contain # {{ comment }} with no escaping: - src/datamodel_code_generator/model/template/TypeAliasAnnotation.jinja2:12 and :19 - src/datamodel_code_generator/model/template/TypeAliasType.jinja2:12 and :19 - src/datamodel_code_generator/model/template/TypeStatement.jinja2:12 and :19 - src/datamodel_code_generator/model/template/pydantic_v2/BaseModel.jinja2:4 - src/datamodel_code_generator/model/template/pydantic_v2/RootModel.jinja2:19 - src/datamodel_code_generator/model/template/pydantic_v2/RootModelTypeAlias.jinja2:13 The pydantic_v2/BaseModel.jinja2:4 site is representative: 2 class {{ class_name }}({{ base_class }}):{% if comment is defined %} # {{ comment }}{% endif %} When the developer-supplied extras file populates comment for a model, the value reaches the template via DataModel.extra_template_data (set in src/datamodel_code_generator/model/base.py:736-742) and Jinja2 interpolates it raw. None of the templates use comment_safe, escape_docstring, or any other line-terminator filter. PoC Complete self contained POC is available at my secret gist: https://gist.github.com/thegr1ffyn/8ad6b8cb3cc2be9d3a0144aeb6896a3f Impact - Who's affected: any developer or CI pipeline that runs datamodel-codegen --extra-template-data <file> where the extras file is influenced by attacker-controlled input. Realistic scenar

⚡ Watch CVE-2026-54654

Get an email if CVE-2026-54654 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-54654

CVE.org record

Embed the live status

CVE-2026-54654 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54654 status](https://www.csirts.com/badge/CVE-2026-54654)](https://www.csirts.com/cve/CVE-2026-54654)