Executive brief
datamodel-code-generator is a tool used to automatically create Python code from data schema definitions. A security flaw was identified where the tool incorrectly shares sensitive login credentials (such as passwords or session tokens) when it is redirected from a trusted website to a different, potentially malicious website while downloading a schema. This could allow an attacker who controls a schema host to steal credentials intended for a legitimate service.
Technical details
A credential leakage vulnerability exists in the `get_body()` function within `src/datamodel_code_generator/http.py`. The component manually handles HTTP redirects but fails to strip sensitive headers when the redirect target belongs to a different origin (scheme, host, or port). An attacker who can influence the redirect chain—either by compromising a schema host or through an open redirect—can capture `Authorization`, `Cookie`, and `Proxy-Authorization` headers. This occurs when users provide credentials via `--http-headers` or URL userinfo. The issue is resolved in version 0.63.0 by ensuring sensitive headers are dropped during cross-origin redirects.
Affected products
- koxudaxi datamodel-code-generator <= 0.62.0
Timeline
- 2026-06-11: patched: Fix merged into main branch
- 2026-06-12: advisory: GitHub Security Advisory GHSA-r5vv-ff45-prp2 published
- 2026-07-28: disclosed: CVE-2026-55403 published to NVD