CVE-2009-3850 describes a critical remote code execution vulnerability affecting Blender versions 2.34, 2.35a, 2.40, and 2.49b. Attackers can exploit this by crafting malicious .blend files containing Python statements within the onLoad action of a ScriptLink SDNA. With a CVSS score of 9.3, this vulnerability has a high severity, allowing unauthenticated remote attackers to achieve complete compromise of confidentiality, integrity, and availability with medium attack complexity. While not listed in CISA's KEV catalog, an ExploitDB proof-of-concept exists, though there is no evidence of active exploitation, Metasploit modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.34CPE matchmatch criteria | cpe:2.3:a:blender:blender:2.34:*:*:*:*:*:*:* | ||
2.35aCPE matchmatch criteria | cpe:2.3:a:blender:blender:2.35a:*:*:*:*:*:*:* | ||
2.40CPE matchmatch criteria | cpe:2.3:a:blender:blender:2.40:*:*:*:*:*:*:* | ||
2.49bCPE matchmatch criteria | cpe:2.3:a:blender:blender:2.49b:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.