Executive brief
datamodel-code-generator is a tool used to automatically create Python code from data schemas. A security flaw allows the tool to be tricked into accessing sensitive internal network resources, such as cloud metadata services or private internal APIs, when processing a malicious URL. If an attacker convinces a user to run the tool against a malicious link, private data from the user's internal network could be captured and embedded directly into the generated Python source code, potentially leading to the theft of credentials or other sensitive information.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the `http.get_body` function within `src/datamodel_code_generator/http.py`. The component uses `httpx.get` with `follow_redirects=True` but fails to validate the host or IP address of the initial URL or any subsequent redirect targets. An attacker can provide a URL that redirects to loopback addresses, RFC1918 private ranges, or cloud metadata services (e.g., 169.254.169.254). Because the tool reflects the response body into the generated Python models as class attributes or docstrings, sensitive data from internal services can be exfiltrated. This issue is fixed in version 0.61.0, which introduces host validation and a new `--allow-private-network` flag for explicit opt-in.
Affected products
- koxudaxi datamodel-code-generator >= 0.9.1, < 0.61.0
Timeline
- 2026-06-08: patched: Fixed in version 0.61.0
- 2026-07-28: advisory: GitHub Advisory GHSA-rfr2-mq9m-x2qx published