{"id":"CVE-2026-34399","summary":"FreeCAD: Arbitrary Code Execution via eval() on untrusted SVG template scale field in BIM TechDraw Page","details":"FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untrusted data from SVG template files. When a user creates a TechDraw page from a malicious SVG template, arbitrary Python code executes. The vulnerable code is in src/Mod/BIM/bimcommands/BimTDPage.py (line 87). This issue is fixed in version 1.1.1.","aliases":["GHSA-chv4-vm6r-wjqj"],"modified":"2026-09-11T03:30:18.140416566Z","published":"2026-08-17T20:50:19.829Z","database_specific":{"cwe_ids":["CWE-95"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34399.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34399.json"},{"type":"ADVISORY","url":"https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-chv4-vm6r-wjqj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34399"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/freecad/freecad","events":[{"introduced":"d29fd7d9cb9fb280a1eb47f55e3c73c46d637ba2"},{"fixed":"0108fd4b4850cc46e625b60e53cea7a7bbe69f8d"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0.19"},{"fixed":"1.1.1"}]}}],"versions":["1.1.0","1.1rc3","1.1rc2","1.1rc1","weekly-2025.11.12","weekly-2025.11.05","weekly-2025.11.02","weekly-2025.10.31","weekly-2025.10.29","weekly-2025.10.22","weekly-2025.10.15","weekly-2025.10.08","weekly-2025.10.01","weekly-2025.09.24","weekly-2025.09.17","weekly-2025.09.12","weekly-2025.09.11","weekly-2025.09.10","weekly-2025.09.03","weekly-2025.08.27","weekly-2025.08.20","weekly-2025.08.13","weekly-2025.08.07","weekly-2025.08.05","weekly-2025.08.04","weekly-2025.07.29","weekly-2025.07.28","weekly-2025.07.26","weekly-2025.07.25","weekly-2025.07.24","weekly-2025.07.21","weekly-2025.07.14","weekly-2025.07.07","weekly-2025.06.30","weekly-2025.06.23","weekly-2025.06.16","weekly-2025.06.09","weekly-2025.06.02","weekly-2025.05.26","weekly-2025.05.19","weekly-2025.05.13","weekly-2025.05.02","weekly-2025.05.06","weekly-2025.04.28","weekly-2025.04.21","0.21rc1","0.20","0.20beta1","0.19"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-34399.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}