Описание
FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM Project Manager Load Template flow passes attacker-controlled FCStd Meta property values for wpposition, wpu, wpv, and wpaxis directly to eval(), allowing arbitrary Python code execution when a user loads a malicious BIM project template. This issue is fixed in version 1.1.1.
Ссылки
EPSS
7.8 High
CVSS3
Дефекты
Связанные уязвимости
A flaw was found in FreeCAD, a 3D parametric modeler. The BIM Project Manager's Load Template function does not properly validate certain properties within a project template. This vulnerability allows a remote attacker to embed malicious Python code into a specially crafted BIM project template. When a user opens this malicious template, the embedded code can be executed, potentially leading to arbitrary code execution on the user's system.
FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...
EPSS
7.8 High
CVSS3