Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been patched via commit c35b8cd.
Metrics
Affected Vendors & Products
References
History
Fri, 06 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been patched via commit c35b8cd. | |
| Title | Mesa: Checking out of untrusted code in `benchmarks.yml` workflow may lead to code execution in privileged runner | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-06T16:30:08.146Z
Reserved: 2026-03-03T20:51:43.483Z
Link: CVE-2026-29075
No data.
Status : Received
Published: 2026-03-06T17:16:34.167
Modified: 2026-03-06T17:16:34.167
Link: CVE-2026-29075
No data.
OpenCVE Enrichment
No data.