PULSE
LIVE34signals / 24h
FEED
ransomchaos reclama a remco.ca · CA · Otherransomqilin reclama a Contacto Garantido · MX · Professional Servicesransomqilin reclama a Universitatea de Vest „Vasile Goldiș” din Arad · RO · Educationransomm3rx reclama a hydraulic-components.net · DE · Manufacturingransomm3rx reclama a createinfor.pt · PT · Professional Servicesransomm3rx reclama a servicebypremier.com · US · Professional Servicesransomexfilsquad reclama a Analog Devices · US · Technologyransomexfilsquad reclama a Bonava · SE · Manufacturingransomexfilsquad reclama a City of Atlanta · US · Government & Defenseransomexfilsquad reclama a City of Houston · US · Government & Defenseransomexfilsquad reclama a Viavi Solutions · US · Technologyransomexfilsquad reclama a Newcastle University · GB · Educationransomexfilsquad reclama a District of Columbia Public Schools · US · Educationransomexfilsquad reclama a Zenith Bank Plc · NG · Financial Servicesransomchaos reclama a remco.ca · CA · Otherransomqilin reclama a Contacto Garantido · MX · Professional Servicesransomqilin reclama a Universitatea de Vest „Vasile Goldiș” din Arad · RO · Educationransomm3rx reclama a hydraulic-components.net · DE · Manufacturingransomm3rx reclama a createinfor.pt · PT · Professional Servicesransomm3rx reclama a servicebypremier.com · US · Professional Servicesransomexfilsquad reclama a Analog Devices · US · Technologyransomexfilsquad reclama a Bonava · SE · Manufacturingransomexfilsquad reclama a City of Atlanta · US · Government & Defenseransomexfilsquad reclama a City of Houston · US · Government & Defenseransomexfilsquad reclama a Viavi Solutions · US · Technologyransomexfilsquad reclama a Newcastle University · GB · Educationransomexfilsquad reclama a District of Columbia Public Schools · US · Educationransomexfilsquad reclama a Zenith Bank Plc · NG · Financial Services
← All CVEs
CVE WatchJul 26, 2026

CVE-2026-63720

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to

CVSS

7.5

High

EPSS

KEV

Exploit Today

0

0-100

Published: Jul 26, 2026 · Last modified: Jul 26, 2026 · CWE-94

EPSS · 30d

Not enough EPSS history yet.

Technical description

datamodel-code-generator prior to version 0.70.0 contains a code injection vulnerability that allows attackers who control input schemas to achieve remote code execution by supplying a malicious customBasePath value containing embedded newlines and a dot-free Python expression. The crafted value is emitted verbatim into a generated 'from ... import ...' statement without identifier validation, causing arbitrary Python code to execute when the generated module is imported.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-656937.2 HIG
38.9%
12Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary OS command execution by injecting Twig expressions into mail templates. Attackers can exploit the unsandboxed Twig environment in TwigView::render(), which lacks SandboxExtension or a SecurityPolicy, to inject malicious expressions such as filter('system') into mail template bodies stored unsanitized in the database, causing automatic payload execution on each subsequent application event that triggers a mail dispatch.2d
CVE-2026-168018.8 HIG
21.0%
6Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.2d
CVE-2026-168008.8 HIG
21.0%
6Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.2d
CVE-2025-7138910.0 CRI
56.9%
17Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose React Server Components (RSC) request handling deserializes attacker-controlled input. A remote attacker can send a crafted RSC request to the server and cause arbitrary code to be executed during server-side processing, without authentication or user interaction. The flaw derives from the upstream Next.js vulnerability CVE-2025-55182 and is resolved in 5.9.9 by updating the affected dependency.2d
CVE-2026-601227.8 HIG
7.1%
2gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot heredoc data block. Attackers can supply a used value containing the string EOD to terminate the heredoc early and append gnuplot system() calls, achieving OS command execution as the user running gpsprof when the generated plot script is processed by gnuplot in polar mode.3d
CVE-2026-47722
18.9%
6nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86,108,119` interpolates the operator-supplied `ListenHost` and `TunDevice` fields raw into a `text/template` that produces the agent's `config.yml`. `internal/web/advanced.go:20-35` accepts both with only `strings.TrimSpace` — no character or shape validation. Version 0.3.2 fixes the issue.2d