What is CVE-2026-34399?
FreeCAD's BIM Workbench (versions 0.19 to 1.1.1) contains a code execution vulnerability via an eval() call on untrusted SVG template files. When a TechDraw page is created from a malicious SVG, arbitrary Python code can run, potentially leading to full system compromise. Users should immediately upgrade to version 1.1.1 or later and avoid untrusted SVG sources.
Azərbaycanca: FreeCAD-in BIM İş Masası komponentində (0.19-dan 1.1.1-ə qədər versiyalarda) zərərli SVG şablon faylları vasitəsilə eval() funksiyasına əsaslanan uzaqdan kod icrası zəifliyi aşkarlanıb. Bu, istifadəçi tərəfindən hazırlanmış TechDraw səhifəsi yaradıldıqda ixtiyari Python kodunun işə düşməsinə səbəb olur, sistemin tam ələ keçirilməsinə yol aça bilər. İstifadəçilərə dərhal 1.1.1 və ya daha yuxarı versiyaya yeniləmə, etibarsız SVG mənbələrindən qaçınmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
What user action is required to exploit the eval() vulnerability in FreeCAD's BIM Workbench?
The user must create a TechDraw page using a malicious SVG template file for the exploit to trigger.
To which version should users upgrade to protect against CVE-2026-34399?
Users are advised to immediately upgrade to FreeCAD version 1.1.1 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.