CVE-2026-73235

NameCVE-2026-73235
DescriptionFreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp by Base::XMLReader::XMLReader() parses attacker-controlled Document.xml from a crafted .FCStd archive without disabling default external entity resolution or external DTD loading. When Document::restore() opens the document, external entities can read local files through the file URI scheme or initiate server-side requests through the http URI scheme, and resolved content can flow through the characters() callback. This issue is fixed in version 1.1.2.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
freecad (PTS)bullseye (security), bullseye0.19.1+dfsg1-2+deb11u1vulnerable
bookworm0.20.2+dfsg1-4vulnerable
trixie1.0.0+dfsg-8+deb13u2vulnerable
sid1.1.1+dfsg-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
freecadsource(unstable)(unfixed)

Notes

https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-cp6c-87x9-xf49
https://github.com/FreeCAD/FreeCAD/pull/31280
Fixed by: https://github.com/FreeCAD/FreeCAD/commit/7d1b8f5806db578db99feb348e55a6b0eaff7c73 (1.1.2)

Search for package or bug name: Reporting problems