Untriaged
Permalink
CVE-2026-34398
7.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
FreeCAD: Arbitrary Code Execution via eval() on untrusted project file metadata in BIM Workbench
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property values for wpposition, wpu, wpv, and wpaxis directly to eval(), allowing arbitrary Python code execution when a user loads a malicious BIM project template. This issue is fixed in version 1.1.1.
References
-
https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-8rfj-7956-6gwf x_refsource_CONFIRM
-
https://github.com/FreeCAD/FreeCAD/pull/28610 x_refsource_MISC
-
https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.1 x_refsource_MISC
Affected products
FreeCAD
- ==>= 0.19, < 1.1.1
Matching in nixpkgs
pkgs.freecad
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-qt6
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-wayland
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
Package maintainers
-
@LordGrimmauld Sören Bender <soeren@benjos.de>
-
@srounce Samuel Rounce <me@samuelrounce.co.uk>
-
@acuteaangle Summer Tea <zestypurple@protonmail.com>