๐Ÿ” CVE Alert

CVE-2026-73235

MEDIUM 6.1

FreeCAD: XXE file read and SSRF via external entity injection in Document.xml SAX parser

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp by Base::XMLReader::XMLReader() parses attacker-controlled Document.xml from a crafted .FCStd archive without disabling default external entity resolution or external DTD loading. When Document::restore() opens the document, external entities can read local files through the file URI scheme or initiate server-side requests through the http URI scheme, and resolved content can flow through the characters() callback. This issue is fixed in version 1.1.2.

CWE CWE-611
Vendor freecad
Product freecad
Published Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for freecad freecad

Be the first to know when new medium vulnerabilities affecting freecad freecad are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

FreeCAD / FreeCAD
< 1.1.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-cp6c-87x9-xf49 github.com: https://github.com/FreeCAD/FreeCAD/pull/31271 github.com: https://github.com/FreeCAD/FreeCAD/pull/31280 github.com: https://github.com/FreeCAD/FreeCAD/commit/7d1b8f5806db578db99feb348e55a6b0eaff7c73 github.com: https://github.com/FreeCAD/FreeCAD/commit/d98eaf1f194400d8a8886fe6780c54f5c68ea2c3 github.com: https://github.com/FreeCAD/FreeCAD/releases/tag/1.1.2