CVE-2026-34789

EUVD-2026-60454
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML directly to PyImport_ImportModule() while restoring a crafted FCStd document, which executes module-level Python code, and the legacy pickle branch also imports an attacker-controlled module and invokes its class constructor through PyObject_CallObject(). This issue is fixed in version 1.1.2.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
7 HIGH
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 7.57%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
freecadfreecad
𝑥
< 1.1.2
CNA
Debian logo
Debian Releases
Debian Product
Codename
freecad
bookworm
vulnerable
forky
1.1.3+dfsg-3
fixed
sid
1.1.3+dfsg-3
fixed
trixie
1.0.0+dfsg-8+deb13u3
fixed
trixie (security)
1.0.0+dfsg-8+deb13u3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
freecad
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
dne
resolute
dne
xenial
needs-triage