CVE-2024-29189

HIGH

PyAnsys Geometry <0.3.3-0.4.11 - Code Injection

Title source: llm
STIX 2.1

Description

PyAnsys Geometry is a Python client library for the Ansys Geometry service and other CAD Ansys products. On file src/ansys/geometry/core/connection/product_instance.py, upon calling this method _start_program directly, users could exploit its usage to perform malicious operations on the current machine where the script is ran. This vulnerability is fixed in 0.3.3 and 0.4.12.

Scores

CVSS v3 7.4
EPSS 0.0012
EPSS Percentile 30.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (2)
ansys/pyansys_geometry 0.3.0 - 0.3.3
pypi/ansys-geometry-core 0.3.0 - 0.3.3PyPI
Published Mar 26, 2024
Tracked Since Feb 18, 2026