CVE-2026-29075
HIGHMesa <=3.5.0 - Code Injection
Title source: llmDescription
Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been patched via commit c35b8cd.
Scores
CVSS v3
8.3
EPSS
0.0007
EPSS Percentile
20.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Classification
CWE
CWE-94
Status
draft
Timeline
Published
Mar 06, 2026
Tracked Since
Mar 07, 2026