#1144349 freecad: CVE-2026-73233 CVE-2026-73234 CVE-2026-73235

Package:
src:freecad
Source:
src:freecad
Submitter:
Salvatore Bonaccorso
Date:
2026-08-22 17:53:02 UTC
Severity:
normal
Tags:
#1144349#5
Date:
2026-08-14 07:06:35 UTC
From:
To:
Hi,

The following vulnerabilities were published for freecad.

CVE-2026-73233[0]:
| FreeCAD is a free and open-source multiplatform 3D parametric
| modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog
| in src/Mod/Fem/Gui/TaskFemConstraintDisplacement.cpp passes the
| xDisplacementFormula, yDisplacementFormula, and zDisplacementFormula
| fields of a Fem::ConstraintDisplacement object through
| TaskDlgFemConstraintDisplacement::accept() into
| Gui::Command::doCommand. The escaping helper neutralizes quotation
| marks but not backslashes, allowing crafted formula text to
| terminate the generated Python string and execute arbitrary Python
| code with the FreeCAD process's privileges when a victim accepts the
| dialog. This issue is fixed in version 1.1.2.


CVE-2026-73234[1]:
| FreeCAD is a free and open-source multiplatform 3D parametric
| modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in
| src/App/PropertyFile.cpp concatenates an attacker-controlled file or
| data attribute from Document.xml with the document transient path
| without rejecting directory components, absolute paths, or parent
| traversal. A crafted .FCStd archive with a matching FileIncluded XML
| attribute and ZIP entry can therefore write attacker-controlled
| content to arbitrary locations accessible to the FreeCAD user,
| potentially enabling persistence, credential compromise,
| configuration replacement, or code execution. This issue is fixed in
| version 1.1.2.


CVE-2026-73235[2]:
| FreeCAD is a free and open-source multiplatform 3D parametric
| modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in
| src/Base/Reader.cpp by Base::XMLReader::XMLReader() parses attacker-
| controlled Document.xml from a crafted .FCStd archive without
| disabling default external entity resolution or external DTD
| loading. When Document::restore() opens the document, external
| entities can read local files through the file URI scheme or
| initiate server-side requests through the http URI scheme, and
| resolved content can flow through the characters() callback. This
| issue is fixed in version 1.1.2.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-73233
https://www.cve.org/CVERecord?id=CVE-2026-73233
[1] https://security-tracker.debian.org/tracker/CVE-2026-73234
https://www.cve.org/CVERecord?id=CVE-2026-73234
[2] https://security-tracker.debian.org/tracker/CVE-2026-73235
https://www.cve.org/CVERecord?id=CVE-2026-73235

Regards,
Salvatore

#1144349#8
Date:
2026-08-22 10:16:32 UTC
From:
To:
Hello,

Bug #1144349 in freecad reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/debian/freecad/-/commit/adefe9d1785dabd13e5bb67f996be0777752e6cc
------------------------------------------------------------------------
New upstream release.
  The new upstream releases fixes: (Closes: #1144349)
    - CVE-2026-73233 - FEM formula incomplete escape
    - CVE-2026-73234 - path traversal
    - CVE-2026-73235 - XXE and SSRF via external entity injection
* Update d/copyright for new release.
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144349

#1144349#15
Date:
2026-08-22 17:51:10 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
freecad, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144349@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Tobias Frost <tobi@debian.org> (supplier of updated freecad package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 22 Aug 2026 18:50:59 +0200
Source: freecad
Architecture: source
Version: 1.1.3+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: FreeCAD Packaging Team <team+freecad-packaging-team@tracker.debian.org>
Changed-By: Tobias Frost <tobi@debian.org>
Closes: 1144349
Changes:
 freecad (1.1.3+dfsg-1) unstable; urgency=medium
 .
   * New upstream release.
     The new upstream releases fixes: (Closes: #1144349)
       - CVE-2026-73233 - FEM formula incomplete escape
       - CVE-2026-73234 - path traversal
       - CVE-2026-73235 - XXE and SSRF via external entity injection
       - CVE-2026-34789 - Arbitrary code execution via PyImport_ImportModule
   * Update d/copyright for new release.
   * Patches maintainance:
     - 2060-fix-linking.patch - unused patch, removed.
   * Ensure a new enough libondselsolver is used.
   * Temporarily disable mash generation with NetGen - See #1145107.
   * Add a autopkgtest to catch broken build-dependencies.
Checksums-Sha1:
 94925acfdfb6d3707f8f78c4f3b27bbe896386df 3755 freecad_1.1.3+dfsg-1.dsc
 35e45fcede87f238e6af92c8acaf0c7a3fdd169b 57829936 freecad_1.1.3+dfsg.orig.tar.xz
 ba0503698671e91905645db7cd055ca8e61a7b78 39784 freecad_1.1.3+dfsg-1.debian.tar.xz
 7b4942c8c274fea80f1a8a13d3adc2fe3c7d0f71 40820 freecad_1.1.3+dfsg-1_source.buildinfo
Checksums-Sha256:
 163b1052750e695cab42ee7f72c9812b5273fa83a9f3d31a850836fef62e5254 3755 freecad_1.1.3+dfsg-1.dsc
 d783843dc377717c462f5330fc20a769ebea0fc8b0898e50507ef35e50b7ddd2 57829936 freecad_1.1.3+dfsg.orig.tar.xz
 cabf6594ceafe258e072778302cca1acac09b57ae4b42626b4dfae9572baa8fe 39784 freecad_1.1.3+dfsg-1.debian.tar.xz
 ade241a8e2d604c8f00d97e8e3bd1d8cd30f7a2780c9713051b6e6fe580aa40d 40820 freecad_1.1.3+dfsg-1_source.buildinfo
Files:
 55f789514dba0e354534620788795496 3755 science optional freecad_1.1.3+dfsg-1.dsc
 2fbebb89173904217d9170f939a34227 57829936 science optional freecad_1.1.3+dfsg.orig.tar.xz
 d3dd6f85cb1c2ecb8847670206671ebb 39784 science optional freecad_1.1.3+dfsg-1.debian.tar.xz
 1cd43c00bb011e4aaec5a0a3438fcfdf 40820 science optional freecad_1.1.3+dfsg-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

wsG7BAEBCgBvBYJqidxKCRDez4SapjV/t0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u
cy5zZXF1b2lhLXBncC5vcme9fzwx4Ujp29XFD3mjv/JogfAYYQ64d1i4SL9qyfPT
MBYhBBPJBPDOCF58NjB5hd7PhJqmNX+3AADYVBAA1D45Zh2O/NophTITphWhzL26
bcvffsCEDSEFW5O4dGt6JDJCxo2NKRQs8VZ68id0AsMRE5YKPNivoQwQ2hnYLjvr
HB3zYoPJnfKEGikwYnLv/H2ZXEobTA6Wf/snJJq3TwiuwSJy2LbV0HU1VTwAIjx1
Jeud6ffAo/HfYEmV2vW+ErRE1Qv1RbrwEm3VOK6/aAmzsq5yycXsw5oTkI0SbWBO
SwDHY9gsxsRG5R7lpsqO2q7iLvZYgBNyt9O6iLDU4oJBQTTmwbNGIGH3VpIh8CMJ
KOBsyoqOofT2zr2PrGiHv4YhnLK6DC2Mk3Y2yM1EmVNjsJd1H6z+RGYQo2n4AxMu
uF7Oy2ee79puuXTgT6Dw2xrVoTfyIzpiMhBgYMTVBLcWCpBlL7IU2dlAsASzZKiK
ZcV1yXXOLh9vsZNgN9lz2i+1KoJGLOaP5TDj6GDYzz1A80ofZ0ZLG6CHYNUCoXmg
xuzxGHJKJfnuvys1ko1nXyiekETC0Sv8clrldDsYAj+YgxiWPstYMA5iW4rpActb
louVpadlZgSnSQhniJCGhZFgclyfGuEvhGRWwZioJZS77KrMW/tlHtMGE3YOMkf3
uIvu0tud2SkUk3P+wpYMoOocmI+MUdiFRdQ3DUc0wWDSI0FLBRNlaP3LnBq0tp1x
pTFTpNnDGv6rZmb9aAI=
=A2O5
-----END PGP SIGNATURE-----