Path traversal in Freecad - #VU153053
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to write arbitrary files outside the intended transient directory.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in VRMLObject::restoreTextureFinished() when restoring VRML resources from a crafted FCStd document. A remote attacker can supply a crafted FCStd document containing traversal resource names to write arbitrary files outside the intended transient directory.
User interaction is required to open the crafted document.