CVE-2026-34789

NameCVE-2026-34789
DescriptionFreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Restore() passes the attacker-controlled module attribute from serialized PropertyPythonObject XML directly to PyImport_ImportModule() while restoring a crafted FCStd document, which executes module-level Python code, and the legacy pickle branch also imports an attacker-controlled module and invokes its class constructor through PyObject_CallObject(). This issue is fixed in version 1.1.2.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6467-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freecad (PTS)bullseye (security), bullseye0.19.1+dfsg1-2+deb11u1vulnerable
bookworm0.20.2+dfsg1-4vulnerable
trixie1.0.0+dfsg-8+deb13u2vulnerable
trixie (security)1.0.0+dfsg-8+deb13u3fixed
sid1.1.3+dfsg-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freecadsourcetrixie1.0.0+dfsg-8+deb13u3DSA-6467-1
freecadsource(unstable)1.1.3+dfsg-1

Notes

https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-493w-pp4h-h77v
Fixed by: https://github.com/FreeCAD/FreeCAD/commit/81b73925ce22610542367301d8eff4259eb9596e (1.1.1)
Fixed by: https://github.com/FreeCAD/FreeCAD/commit/e2dc6c8172673642c6856b8b3a5a6accefb18279 (1.1.2)

Search for package or bug name: Reporting problems