{"id":"CVE-2024-8374","summary":"Arbitrary Code Injection in Cura","details":"UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via the 3MF format reader (/plugins/ThreeMFReader.py). The vulnerability arises from improper handling of the drop_to_buildplate property within 3MF files, which are ZIP archives containing the model data. When a 3MF file is loaded in Cura, the value of the drop_to_buildplate property is passed to the Python eval() function without proper sanitization, allowing an attacker to execute arbitrary code by crafting a malicious 3MF file. This vulnerability poses a significant risk as 3MF files are commonly shared via 3D model databases.","modified":"2026-08-12T03:51:48.071158266Z","published":"2024-09-03T10:01:12.871Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"5.7.0-beta.1"},{"last_affected":"5.7.2"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"5.7.0-beta.1"},{"fixed":"5.7.2"}],"source":"DESCRIPTION"}],"cna_assigner":"Checkmarx","cwe_ids":["CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8374.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/8xxx/CVE-2024-8374.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-8374"},{"type":"FIX","url":"https://github.com/Ultimaker/Cura/commit/285a241eb28da3188c977f85d68937c0dad79c50"},{"type":"PACKAGE","url":"https://github.com/Ultimaker/Cura"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ultimaker/cura","events":[{"introduced":"04ddb8e6e0d5fb66a7f42dca18d3a5aed9cc6abe"},{"fixed":"285a241eb28da3188c977f85d68937c0dad79c50"}],"database_specific":{"extracted_events":[{"introduced":"5.7.0-NA"},{"last_affected":"5.7.0-NA"},{"introduced":"5.7.1"},{"last_affected":"5.7.1"},{"introduced":"5.7.2-rc2"},{"last_affected":"5.7.2-rc2"}],"source":["CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:ultimaker:ultimaker_cura:5.7.0:-:*:*:*:*:*:*","cpe:2.3:a:ultimaker:ultimaker_cura:5.7.1:*:*:*:*:*:*:*","cpe:2.3:a:ultimaker:ultimaker_cura:5.7.2:rc2:*:*:*:*:*:*"]}}],"versions":["5.7.0-NA","5.7.1","5.7.2-rc2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-8374.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}