CVE-2026-34399

NameCVE-2026-34399
DescriptionFreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a malicious SVG template, arbitrary Python code executes. The vulnerable code is in src/Mod/BIM/bimcommands/BimTDPage.py (line 87). This issue is fixed in version 1.1.1.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6467-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freecad (PTS)bullseye (security), bullseye0.19.1+dfsg1-2+deb11u1vulnerable
bookworm0.20.2+dfsg1-4vulnerable
trixie1.0.0+dfsg-8+deb13u2vulnerable
trixie (security)1.0.0+dfsg-8+deb13u3fixed
sid1.1.3+dfsg-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freecadsourcetrixie1.0.0+dfsg-8+deb13u3DSA-6467-1
freecadsource(unstable)1.1.1+dfsg-1

Notes

https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-chv4-vm6r-wjqj

Search for package or bug name: Reporting problems