Listen to this Post
- When processing an attacker-controlled Protobuf schema, vulnerable library versions fail to sanitize import paths.
- The vulnerability resides in how the parser handles weak import statements declared within `.proto` files.
- An attacker can supply a malicious schema locally via file input or remotely via a network URL.
- The extraction mechanism relies on a regular expression pattern that captures the target import path freely.
- No character restrictions or sanitization checks are enforced on the captured import string.
- The captured path is subsequently joined with a temporary directory base using Python pathlib semantics.
- Python pathlib treats absolute paths on the right operand as absolute destinations that discard the base.
- This allows an attacker to specify absolute paths and write files anywhere writable by the process.
- Similarly, relative path traversal sequences utilizing double dots allow climbing out of the sandbox directory.
- The write operation automatically creates intermediate parent directories using recursive directory creation.
- Written content consists of a fixed Protobuf syntax declaration followed by a newline character.
- These filesystem modifications execute immediately inside the input preparer context enter method.
- Execution occurs before the underlying protocol compiler runs and processes the schema definition.
- Even though the compiler ultimately rejects the malformed virtual path, filesystem changes persist.
- A separate existence check intended to prevent accidental overwrites fails due to mismatched base directories.
- The existence guard checks inclusion paths while the write operation targets the temporary weak import folder.
- For relative traversal paths, this mismatch causes the guard to check the wrong location entirely.
- As a result, pre-existing files outside the temporary sandbox can be silently overwritten.
- The attack requires a user or CI pipeline to process the malicious schema using vulnerable tool versions.
- The impact is categorized under integrity loss since attackers can overwrite critical build and configuration files.
- Direct remote code execution is not achieved, but file corruption and denial of service are fully realizable.
- The underlying root cause mirrors previous path traversal flaws discovered in JSON Schema and XSD parsers.
- Affected components include datamodel-code-generator version 0.80.0 and unpatched main branch commits.
- The flaw grants attackers control over file placement within the security context of the running process.
- Developers using automated schema ingestion pipelines are at highest risk of targeted file overwrite attacks.
- Security researchers demonstrated the vulnerability using local input and remote HTTP server PoC scripts.
- The vendor resolved the issue by introducing strict path resolution and sandbox containment checks.
- Any resolved candidate path escaping the designated temporary directory now triggers an immediate schema parse error.
- Input preparation failures also ensure complete cleanup of temporary directories to remove residual artifacts.
- Users are strongly advised to upgrade to patched releases once available and avoid untrusted schema inputs.
DailyCVE Form:
Platform: datamodel-code-generator
Version: 0.80.0 and prior
Vulnerability: Path Traversal Write
Severity: High (7.5)
date: September 2026
Prediction: Patched in main
(end of form)
What Undercode Say
Bash Commands and PoC Code
pip install datamodel-code-generator==0.80.0 bash poc/reproduce.sh bash poc/reproduce-url.sh
WEAK_IMPORT_PATTERN = re.compile(r'^\simport\s+weak\s+"([^"]+)"\s;', re.MULTILINE) def _write_missing_weak_imports(self): for import_path in WEAK_IMPORT_PATTERN.findall(text): stub = self.weak_import_dir / import_path stub.parent.mkdir(parents=True, exist_ok=True) stub.write_text(syntax, encoding=self.parser.encoding)
Exploit: (Educational Purposes!)
An attacker creates a malicious `.proto` file named `evil.proto` containing payload import statements:
import weak "/home/victim/.config/x"; import weak "../../overwrite_me.txt";
When a victim processes this schema using vulnerable versions of datamodel-code-generator via CLI or API (--input or --url), the `_write_missing_weak_imports` method triggers during __enter__. Because absolute paths replace the base operand in Python’s pathlib, and relative `..` sequences escape the temporary sandbox, arbitrary files are created or overwritten with `syntax = “proto2”;` before `protoc` compiles the schema.
Protection: from this CVE
The vulnerability is mitigated by resolving candidate paths and verifying containment within the designated temporary directory before creating directories or writing files. If a resolved path escapes the sandbox, a `SchemaParseError` is raised immediately. Users should upgrade to patched versions once released, avoid processing untrusted schemas from unauthenticated remote URLs, and run code generation workflows in restricted sandbox environments.
Impact:
Overwrite of source code, configuration files, `.env` files, lock files, or `__init__.py` / entry-point files leading to project corruption and broken builds.
Arbitrary directory tree creation and file dropping into watched or auto-loaded locations, causing denial of service.
Although direct remote code execution is not demonstrated due to the constrained content (syntax = "proto{2,3}";), integrity loss is severe (CVSS 7.5).
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

