Untriaged
Permalink
CVE-2026-34399
7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
FreeCAD: Arbitrary Code Execution via eval() on untrusted SVG template scale field in BIM TechDraw Page
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a malicious SVG template, arbitrary Python code executes. The vulnerable code is in src/Mod/BIM/bimcommands/BimTDPage.py (line 87). This issue is fixed in version 1.1.1.
References
-
https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-chv4-vm6r-wjqj x_refsource_CONFIRM
-
https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.1 x_refsource_MISC
Affected products
FreeCAD
- ==>= 0.19, < 1.1.1
Matching in nixpkgs
pkgs.freecad
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-qt6
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-wayland
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
Package maintainers
-
@LordGrimmauld Sören Bender <soeren@benjos.de>
-
@srounce Samuel Rounce <me@samuelrounce.co.uk>
-
@acuteaangle Summer Tea <zestypurple@protonmail.com>