Insecure DLL loading in Freecad - #VU153055

 

Insecure DLL loading in Freecad - #VU153055

Published: October 1, 2026


Vulnerability identifier: #VU153055
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-427
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to an uncontrolled search path element in FreeCAD.exe when loading libCgGL.DLL, CgGL.DLL, or TDxNavLib.DLL during application launch. A local user can place a malicious DLL in an attacker-writable directory listed in the PATH environment variable to execute arbitrary code.

User interaction is required to launch the application.


Affected software

Freecad

Remediation

Install security update from vendor's website.

Freecad - update to 1.0.2

External References

Related Security Bulletins