CVE-2026-34398 | FreeCAD up to 1.1.0 BIM Project Manager BimProjectManager.py eval wpposition/wpu/wpv/wpaxis eval injection

SecurityVulns

A vulnerability labeled as critical has been found in FreeCAD up to 1.1.0. Affected by this issue is the function eval of the file src/Mod/BIM/bimcommands/BimProjectManager.py of the component BIM Project Manager. Such manipulation of the argument wpposition/wpu/wpv/wpaxis leads to improper neutralization of directives in dynamically evaluated code.

This vulnerability is documented as CVE-2026-34398. The attack can be executed remotely. There is not any exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More