DSA-6467-1 freecad - security update
Multiple vulnerabilities were discovered in FreeCAD, a parametric 3D CAD modeller, which may result in the execution of arbitrary code, the disclosure of local files or requests to arbitrary hosts when a crafted FCStd document or template is processed. https://security-tracker.debian.org/tracker/DSA-6467-1
CSIRTS triage
- What
- FreeCAD contains multiple vulnerabilities allowing arbitrary code execution, local file disclosure, and requests to arbitrary hosts when processing crafted FCStd documents or templates.
- Who is affected
- Systems running FreeCAD and processing untrusted FCStd documents or templates are affected.
- Urgency
- High urgency; arbitrary code execution and file disclosure are possible from crafted documents.
- Action
- Apply Debian security update DSA-6467-1 for FreeCAD.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FreeCAD
Get an email when a new FreeCAD advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00378.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-343980.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-343990.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-347890.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-732330.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-732340.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-732350.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-34398 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34399 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-34789 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73233 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73234 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-73235 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highCVE-2026-34789: FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App…nvd
- highCVE-2026-34399: FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, …nvd
- highCVE-2026-34398: FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, …nvd
- mediumCVE-2026-73235: FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xer…nvd
- highCVE-2026-73234: FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, Propert…nvd
- unknownCVE-2026-73233: FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM…nvd
More from Debian Security Advisories
- unknownDSA-6468-1 emacs - security update2026-08-26
- unknownDSA-6465-1 openssl - security update2026-08-25
- unknownDSA-6464-1 erlang - security update2026-08-25
- unknownDSA-6466-1 linux - security update2026-08-25
- unknownDSA-6463-1 webkit2gtk - security update2026-08-24