What is CVE-2026-34398?
CVE-2026-34398 is a critical vulnerability in FreeCAD's BIM Project Manager that allows remote code execution (RCE) by passing attacker-controlled values directly to the eval() function. It affects versions 0.19 through 1.1.1 and can be exploited via malicious FCStd files. Users are urged to update to version 1.1.1 or later immediately.
Azərbaycanca: CVE-2026-34398 boşluğu FreeCAD-in BIM Project Manager bölməsində eval() funksiyasının təhlükəli istifadəsi səbəbindən uzaqdan kod icrasına (RCE) imkan verir. Bu, xüsusi hazırlanmış FCStd faylı vasitəsilə sistemi təhlükəyə ata bilər. İstifadəçilərə dərhal 1.1.1 və ya daha yuxarı versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
Which component of FreeCAD does CVE-2026-34398 affect?
The vulnerability exists in FreeCAD's BIM Project Manager due to dangerous use of the eval() function.
What is the recommended mitigation for CVE-2026-34398?
Users are urged to update FreeCAD to version 1.1.1 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.