Insecure DLL loading in Freecad - #VU153055
Published: October 1, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to an uncontrolled search path element in FreeCAD.exe when loading libCgGL.DLL, CgGL.DLL, or TDxNavLib.DLL during application launch. A local user can place a malicious DLL in an attacker-writable directory listed in the PATH environment variable to execute arbitrary code.
User interaction is required to launch the application.