Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.
2009-11-06T15:30:00.577
2025-04-09T00:30:58.490
Deferred
CVSSv2: 9.3 (HIGH)
AV:N/AC:M/Au:N/C:C/I:C/A:C
8.6
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | blender | blender | 2.34 | Yes |
Application | blender | blender | 2.35a | Yes |
Application | blender | blender | 2.40 | Yes |
Application | blender | blender | 2.49b | Yes |