CVE-2026-29075
Mesa: Checking out of untrusted code in `benchmarks.yml` workflow may lead to code execution in privileged runner
CVSS Score
8.3
EPSS Score
0.0%
EPSS Percentile
0th
Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been patched via commit c35b8cd.
| CWE | CWE-94 |
| Vendor | mesa |
| Product | mesa |
| Published | Mar 6, 2026 |
| Last Updated | Mar 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for mesa mesa
Be the first to know when new high vulnerabilities affecting mesa mesa are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
Low
Affected Versions
mesa / mesa
<= 3.5.0