CVE-2026-73234
Last modified
CVE-2026-73234 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the document transient path without rejecting directory components, absolute paths, or parent traversal. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp concatenates an attacker-controlled file or data attribute from Document.xml with the document transient path without rejecting directory components, absolute paths, or parent traversal. A crafted .FCStd archive with a matching FileIncluded XML attribute and ZIP entry can therefore write attacker-controlled content to arbitrary locations accessible to the FreeCAD user, potentially enabling persistence, credential compromise, configuration replacement, or code execution. This issue is fixed in version 1.1.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FreeCAD | FreeCAD | < 1.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-73234?
How severe is CVE-2026-73234?
How do I fix CVE-2026-73234?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-73229Django REST framework is a powerful and flexible toolkit for…4.3
- CVE-2026-7323Memory safety bugs present in Thunderbird ESR 140.10.0 and T…7.3
- CVE-2026-73230Ente provides end-to-end encrypted cloud services and securi…5.9
- CVE-2026-73231Faker generates massive amounts of fake data in the browser …7.8
- CVE-2026-73232ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffu…7.5
- CVE-2026-73233FreeCAD is a free and open-source multiplatform 3D parametri…8.5
- CVE-2026-73235FreeCAD is a free and open-source multiplatform 3D parametri…6.1
- CVE-2026-73236Incorrect Authorization vulnerability in Apache Syncope. …7.5
- CVE-2026-73237XSS vulnerability in Markdown handling in Apache Allura. Th…6.1
- CVE-2026-73238XSS vulnerability in code display in Apache Allura. This is…6.1
- CVE-2026-73239Insecure Direct Object Reference (IDOR) due to missing permi…6.5
- CVE-2026-7324Memory safety bugs present in Thunderbird 150.0.0. Some of t…7.3
Are you affected by CVE-2026-73234?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
