VAITP Dataset

← Back to the dataset

CVE-2026-34398

Code execution in FreeCAD BIM by loading a malicious project template.

  • CVSS 7.8
  • 95
  • Input Validation and Sanitization
  • Local

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property values for wpposition, wpu, wpv, and wpaxis directly to eval(), allowing arbitrary Python code execution when a user loads a malicious BIM project template. This issue is fixed in version 1.1.1.

CWE
95
CVSS base score
7.8
Published
2026-08-17
OWASP
A03 Injection
Orthogonal defect classification
Checking
Code defect classification
Missing Check
Category
Input Validation and Sanitization
Subcategory
Command Injection
Accessibility scope
Local
Impact
Arbitrary Code Execution
Affected component
FreeCAD

Solution

Upgrade FreeCAD to version 1.1.1 or later.

Vulnerable code sample

# Simplified representation from src/Mod/BIM/bimcommands/BimProjectManager.py
class BimProjectManager:
    def load_template_properties(self, document):
        """
        Loads working plane properties from a BIM project template.
        The 'document' object has a 'Meta' attribute, which is a dict
        of properties loaded from an untrusted FCStd file.
        """
        if not hasattr(document, "Meta"):
            return

        meta = document.Meta

        if "wpposition" in meta:
            try:
                # VULNERABLE: Attacker-controlled property value is passed to eval()
                pos_tuple = eval(meta["wpposition"])
                # In the real application, pos_tuple would be used to set a
                # FreeCAD.Vector object for the user interface.
            except Exception:
                # Error handling simplified for demonstration
                pass

        # Other properties like 'wpu', 'wpv', and 'wpaxis' were
        # handled with the same vulnerable pattern.

Patched code sample

import ast

# Simplified representation from src/Mod/BIM/bimcommands/BimProjectManager.py
class BimProjectManager:
    def load_template_properties(self, document):
        """
        Loads working plane properties from a BIM project template.
        The 'document' object has a 'Meta' attribute, which is a dict
        of properties loaded from an untrusted FCStd file.
        """
        if not hasattr(document, "Meta"):
            return

        meta = document.Meta

        if "wpposition" in meta:
            try:
                # FIX: Use ast.literal_eval to safely parse simple data literals
                pos_tuple = ast.literal_eval(meta["wpposition"])
                # In the real application, pos_tuple would be used to set a
                # FreeCAD.Vector object for the user interface.
            except (ValueError, SyntaxError):
                # Error handling simplified for demonstration
                pass

        # Other properties like 'wpu', 'wpv', and 'wpaxis' were
        # handled with the same vulnerable pattern.

Payload

__VAITP_MODEL_REFUSED__

Cite this entry

@misc{vaitp:cve202634398,
  title        = {{Code execution in FreeCAD BIM by loading a malicious project template.}},
  author       = {Bogaerts, Fr\'ed\'eric and Ivaki, Naghmeh and Fonseca, Jos\'e},
  year         = {2026},
  note         = {VAITP Python Vulnerability Dataset, entry CVE-2026-34398},
  howpublished = {\url{https://netpack.pt/vaitp/vulnerability/CVE-2026-34398/}}
}
Introducing the "VAITP dataset": a specialized repository of Python vulnerabilities and patches, meticulously compiled for the use of the security research community. As Python's prominence grows, understanding and addressing potential security vulnerabilities become crucial. Crafted by and for the cybersecurity community, this dataset offers a valuable resource for researchers, analysts, and developers to analyze and mitigate the security risks associated with Python. Through the comprehensive exploration of vulnerabilities and corresponding patches, the VAITP dataset fosters a safer and more resilient Python ecosystem, encouraging collaborative advancements in programming security.

The supreme art of war is to subdue the enemy without fighting.

Sun Tzu – “The Art of War”

:: Shaping the future through research and ingenuity ::