FreeCAD是FreeCAD组织的一款三维参数化计算机辅助设计软件。 FreeCAD 1.1.2之前版本存在代码注入漏洞,该漏洞源于PropertyPythonObject::Restore()函数将攻击者控制的模块属性直接传递给PyImport_ImportModule(),并在恢复特制FCStd文档时执行模块级Python代码,可能导致代码注入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34399 | 7.8 HIGH | FreeCAD: Arbitrary Code Execution via eval() on untrusted SVG template scale field in BIM |
| CVE-2026-34398 | 7.8 HIGH | FreeCAD: Arbitrary Code Execution via eval() on untrusted project file metadata in BIM Wor |
No comments yet