Untriaged
Permalink
CVE-2026-34789
7.0 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
Activity log
- Created suggestion
FreeCAD: Arbitrary code execution via unsandboxed PyImport_ImportModule in PropertyPythonObject::Restore
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML directly to PyImport_ImportModule() while restoring a crafted FCStd document, which executes module-level Python code, and the legacy pickle branch also imports an attacker-controlled module and invokes its class constructor through PyObject_CallObject(). This issue is fixed in version 1.1.2.
References
-
https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-493w-pp4h-h77v x_refsource_CONFIRM
-
https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.2 x_refsource_MISC
Affected products
FreeCAD
- ==< 1.1.2
Matching in nixpkgs
pkgs.freecad
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-qt6
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
pkgs.freecad-wayland
General purpose Open Source 3D CAD/MCAD/CAx/CAE/PLM modeler
Package maintainers
-
@LordGrimmauld Sören Bender <soeren@benjos.de>
-
@srounce Samuel Rounce <me@samuelrounce.co.uk>
-
@acuteaangle Summer Tea <zestypurple@protonmail.com>