Path traversal in Freecad - #VU153053

 

Path traversal in Freecad - #VU153053

Published: October 1, 2026


Vulnerability identifier: #VU153053
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to write arbitrary files outside the intended transient directory.

The vulnerability exists due to improper limitation of a pathname to a restricted directory in VRMLObject::restoreTextureFinished() when restoring VRML resources from a crafted FCStd document. A remote attacker can supply a crafted FCStd document containing traversal resource names to write arbitrary files outside the intended transient directory.

User interaction is required to open the crafted document.


Affected software

Freecad

Remediation

Install security update from vendor's website.

Freecad - update to 1.1.4

External References

Related Security Bulletins