Path traversal in Freecad - #VU153054
Published: October 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to write arbitrary files.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in PropertyPostDataObject::RestoreDocFile() when extracting VTK multiblock data from a crafted .FCStd file. A remote attacker can trick the victim into opening a crafted .FCStd file to write arbitrary files.
The FEM module is automatically loaded when the document contains a Fem::FemPostPipeline object, so the FEM workbench does not need to be open.