PatchSiren

FreeCAD CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM FreeCAD CVE published 2026-08-11

CVE-2026-73235

CVE-2026-73235 is a vulnerability in FreeCAD, a free and open-source multiplatform 3D parametric modeler. The issue arises from the Xerces SAX2 XMLReader in src/Base/Reader.cpp, which parses attacker-controlled Document.xml from a crafted .FCStd archive without disabling default external entity resolution or external DTD loading. This allows for potential local file reads or server-side requests when the [truncated]

HIGH FreeCAD CVE published 2026-08-11

CVE-2026-73234

A vulnerability in FreeCAD's PropertyFileIncluded::Restore() function allows for arbitrary file writing when a crafted .FCStd archive is opened. This issue is fixed in version 1.1.2. The vulnerability arises from the function's failure to properly validate file paths, allowing an attacker to write to arbitrary locations. FreeCAD users, administrators, and developers should assess exposure and prioritize u [truncated]

HIGH FreeCAD CVE published 2026-08-11

CVE-2026-73233

This CVE debrief provides an executive overview of CVE-2026-73233, a high-severity vulnerability in FreeCAD's FEM Displacement Constraint task dialog. The vulnerability allows arbitrary Python code execution via crafted formula text. Affected product deployments exist in managed environments where untrusted input is processed. The likely operational impact includes potential for arbitrary Python code exec [truncated]