CVE-2026-34398
Code execution in FreeCAD BIM by loading a malicious project template.
- CVSS 7.8
- 95
- Input Validation and Sanitization
- Local
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property values for wpposition, wpu, wpv, and wpaxis directly to eval(), allowing arbitrary Python code execution when a user loads a malicious BIM project template. This issue is fixed in version 1.1.1.
- CWE
- 95
- CVSS base score
- 7.8
- Published
- 2026-08-17
- OWASP
- A03 Injection
- Orthogonal defect classification
- Checking
- Code defect classification
- Missing Check
- Category
- Input Validation and Sanitization
- Subcategory
- Command Injection
- Accessibility scope
- Local
- Impact
- Arbitrary Code Execution
- Affected component
- FreeCAD
Solution
Upgrade FreeCAD to version 1.1.1 or later.
Vulnerable code sample
# Simplified representation from src/Mod/BIM/bimcommands/BimProjectManager.py
class BimProjectManager:
def load_template_properties(self, document):
"""
Loads working plane properties from a BIM project template.
The 'document' object has a 'Meta' attribute, which is a dict
of properties loaded from an untrusted FCStd file.
"""
if not hasattr(document, "Meta"):
return
meta = document.Meta
if "wpposition" in meta:
try:
# VULNERABLE: Attacker-controlled property value is passed to eval()
pos_tuple = eval(meta["wpposition"])
# In the real application, pos_tuple would be used to set a
# FreeCAD.Vector object for the user interface.
except Exception:
# Error handling simplified for demonstration
pass
# Other properties like 'wpu', 'wpv', and 'wpaxis' were
# handled with the same vulnerable pattern.Patched code sample
import ast
# Simplified representation from src/Mod/BIM/bimcommands/BimProjectManager.py
class BimProjectManager:
def load_template_properties(self, document):
"""
Loads working plane properties from a BIM project template.
The 'document' object has a 'Meta' attribute, which is a dict
of properties loaded from an untrusted FCStd file.
"""
if not hasattr(document, "Meta"):
return
meta = document.Meta
if "wpposition" in meta:
try:
# FIX: Use ast.literal_eval to safely parse simple data literals
pos_tuple = ast.literal_eval(meta["wpposition"])
# In the real application, pos_tuple would be used to set a
# FreeCAD.Vector object for the user interface.
except (ValueError, SyntaxError):
# Error handling simplified for demonstration
pass
# Other properties like 'wpu', 'wpv', and 'wpaxis' were
# handled with the same vulnerable pattern.Payload
__VAITP_MODEL_REFUSED__
Cite this entry
@misc{vaitp:cve202634398,
title = {{Code execution in FreeCAD BIM by loading a malicious project template.}},
author = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
year = {2026},
note = {VAITP Python Vulnerability Dataset, entry CVE-2026-34398},
howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-34398/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.
The supreme art of war is to subdue the enemy without fighting.
Sun Tzu – “The Art of War”
:: Shaping the future through research and ingenuity ::
