freecad
Fail
Audited by Socket on Aug 3, 2026
1 alert found:
MalwareMalwarescripts/freecad-bridge.py
HIGHMalwareHIGH
scripts/freecad-bridge.py
High security risk. This module is an unauthenticated localhost TCP/HTTP-like bridge that can execute arbitrary Python code provided by a client via exec(), including code loaded from an attacker-supplied file path, with FreeCAD/Gui objects exposed to the execution namespace. It also returns full tracebacks/output to the caller (information disclosure) and performs a local status file write as a side effect. The “cross-origin” check is header-based and does not provide real authorization for a local TCP attacker. If this module is present in a supply chain, treat it as a strong indicator of an execution backdoor/bridge capability rather than a benign utility.
Confidence: 90%Severity: 100%
Audit Metadata