FreeCAD是FreeCAD组织的一款参数化三维计算机辅助设计软件。 FreeCAD 1.1.2之前版本存在代码注入漏洞,该漏洞源于src/Mod/Fem/Gui/TaskFemConstraintDisplacement.cpp中的FEM Displacement Constraint任务对话框在传递xDisplacementFormula、yDisplacementFormula和zDisplacementFormula字段时,转义助手仅中和引号而未处理反斜杠,导致特制公式文本可终止生成的Pytho
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73234 | 7.8 HIGH | FreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute i |
| CVE-2026-73235 | 6.1 MEDIUM | FreeCAD: XXE file read and SSRF via external entity injection in Document.xml SAX parser |
No comments yet