A vulnerability, which was classified as critical, was found in koxudaxi datamodel-code-generator up to 0.69.x. Impacted is an unknown function. The manipulation of the argument customBasePath results in code injection.

This vulnerability is reported as CVE-2026-63720. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.