CVE-2026-29075
Last modified
CVE-2026-29075 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been patched via commit c35b8cd.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mesa Project | Mesa | <= 3.5.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-29075?
How severe is CVE-2026-29075?
How do I fix CVE-2026-29075?
Are you affected by CVE-2026-29075?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
