PT-2026-70895 · Freecad · Freecad

CVE-2026-73234

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeCAD versions prior to 1.1.2
Description The PropertyFileIncluded::Restore() function in src/App/PropertyFile.cpp fails to properly validate file or data attributes from Document.xml. It concatenates these attacker-controlled attributes with the document transient path without rejecting absolute paths, directory components, or parent traversal (a technique used to access files and directories outside the intended folder). Consequently, a specially crafted .FCStd archive containing a matching FileIncluded XML attribute and ZIP entry can write arbitrary content to any location accessible to the user. This could lead to code execution, configuration replacement, credential compromise, or persistence.
Recommendations Update to version 1.1.2.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73234
GHSA-5VQH-3V38-JW2R

Affected Products

Freecad